Skip to main content
Glama
OLGTX303

sift-forensic-mcp

by OLGTX303

run_log2timeline

Creates a forensic timeline from a Windows partition by running log2timeline, outputting a .plaso file for analysis.

Instructions

Start log2timeline timeline creation (long-running). Poll with get_timeline_status.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
output_fileNoPath for .plaso output file
partitionNoBlock device of Windows partition
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Without annotations, the description carries the behavioral burden. It discloses the tool is long-running and async, but does not detail side effects, resource usage, or concurrency behavior.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences, no fluff. Front-loads the main action and immediately follows with crucial polling instruction.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a tool with 2 params and no output schema, the description covers basic purpose and async nature. However, it omits what constitutes a valid output file path, partition format, or error handling.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% (both parameters have clear descriptions). The tool description adds no extra parameter information, so baseline score of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool starts log2timeline timeline creation, a specific action on a specific resource. It distinguishes from sibling get_timeline_status by indicating polling for status.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly tells the agent to poll with get_timeline_status, indicating when to use this tool (to start) and when to use a sibling (to check status). It hints at long-running nature, though lacks explicit when-not-to-use or alternatives.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Install Server

Other Tools

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/OLGTX303/find-evil-sift-agent'

If you have feedback or need assistance with the MCP directory API, please join our Discord server