Skip to main content
Glama

Diff two Rego policies

rego_policy_diff

Compare two Rego policies by evaluating the same query against both and returning equality, raw results, and differing paths. Verify refactors preserve behavior or locate divergences.

Instructions

Evaluate the same query against two policies (or two versions of the same policy) and compare the results. Both evaluations run in parallel. Returns equal: true/false, the raw result from each side, and changedPaths -- the dot/bracket paths that differ. Useful for verifying that a refactor preserves behavior, or understanding exactly where two policies diverge. Each side takes either inline source (sourceA/sourceB) or a file/directory path (pathA/pathB). The same input and query are used for both evaluations.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
inputNoInline input document (JSON). Mutually exclusive with inputPath.
pathANoFile or directory path for policy A. Must be inside an allowed root. Mutually exclusive with sourceA.
pathBNoFile or directory path for policy B. Must be inside an allowed root. Mutually exclusive with sourceB.
queryYesThe query to evaluate against both policies, e.g. "data.example.allow".
sourceANoInline Rego source for policy A. Mutually exclusive with pathA.
sourceBNoInline Rego source for policy B. Mutually exclusive with pathB.
dataPathsNoAdditional data or policy paths loaded for both evaluations. Each must be inside an allowed root.
inputPathNoPath to a JSON input file. Must be inside an allowed root. Mutually exclusive with input.
v0CompatibleANoRead policy A as Rego v0 (`--v0-compatible`), the syntax before OPA 1.0. Set this and leave `v0CompatibleB` off to compare a legacy policy with its migrated copy.
v0CompatibleBNoRead policy B as Rego v0 (`--v0-compatible`).

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed2 schema fields changedv0.8.0
    • addedInput schema / properties / v0CompatibleA
      Added value: +{
      +  "description": "Read policy A as Rego v0 (`--v0-compatible`), the syntax before OPA 1.0. Set this and leave `v0CompatibleB` off to compare a legacy policy with its migrated copy.",
      +  "type": "boolean"
      +}
    • addedInput schema / properties / v0CompatibleB
      Added value: +{
      +  "description": "Read policy B as Rego v0 (`--v0-compatible`).",
      +  "type": "boolean"
      +}
  2. Addedv0.1.13

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Adds real behavioral context beyond the annotations: both evaluations run in parallel, the same input/query are shared across both sides, and the return shape (equal, raw result per side, changedPaths) is spelled out. The annotations (readOnlyHint=false, openWorldHint=true) are covered without contradiction.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Four sentences, all earning their place, with the core purpose and the return contract front-loaded ahead of the parameter pairing details. Slightly denser than necessary but no wasted filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 10-parameter tool with no output schema, the description still explains the return values (equal, per-side result, changedPaths) and the A/B source-or-path model, so an agent can call it correctly without inferring anything critical.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is already 100%, so the baseline is 3, but the description adds the cross-parameter semantics the schema only states per-field: the A/B sides each accept either inline source or a path, and both sides share one input and query. That mutual-exclusivity and pairing logic is genuinely additive.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Evaluate the same query against two policies and compare the results'), and is clearly distinguishable from siblings like rego_eval or rego_eval_with_explain which evaluate a single policy. An agent knows exactly what this does without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives concrete motivating use cases -- 'verifying that a refactor preserves behavior' and 'understanding exactly where two policies diverge' -- which tells the agent when this tool is the right choice. It stops short of naming an alternative tool or stating when NOT to use it, so it doesn't reach the top tier.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.