Skip to main content
Glama

risky_steps

Check what coding agents really did: force pushes, recursive deletes, dropped tables, sudo changes. Use before trusting their work or audit for dangerous actions.

Instructions

Risky things agents did, each with when, which agent and the command: force pushes, recursive deletes, git changes thrown away, dropped database tables, scripts piped from the internet, sudo and permission changes, force-stopped programs, changes to .env and other secret files, and the same command failing again and again. Use it for "did my agents do anything dangerous?" or before trusting their work. For a project (default: this one, the last 24 hours) or one session (all of it).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
sinceNoOnly work since then: minutes ago ("90") or a time ("2026-10-04T09:00").
projectNoThe project: its folder's path (best: dotpals matches where each agent works, so same-named folders, a monorepo's packages and worktrees stay apart) or its name. Default: the folder this server runs in.
sessionNoA session ID from agents_now (or its first characters). Default: the newest session in the project.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.10.0

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the behavioral burden and does disclose useful traits beyond the schema: the detection categories and the scoping defaults (project = this one, last 24 hours; session = whole session). It still says nothing about whether it's read-only, result volume, or performance, which keeps it below a 5.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The long enumeration in the first sentence is dense but each item earns its place by defining the tool's detection scope, and the usage conditions follow immediately. It is slightly run-on but front-loaded and waste-free.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

There is no output schema, so the description compensates by stating what each entry contains ("when, which agent and the command") and by covering scope and time defaults. An agent has everything needed to call it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so baseline is 3, but the description adds a default time window ("the last 24 hours") that the schema's `since` parameter does not state, and clarifies session scope means "all of it." That is genuine added meaning over the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

It names a specific concept (risky agent actions) and enumerates the concrete verbs/events that qualify: force pushes, recursive deletes, dropped tables, sudo, .env edits, repeated failures. An agent can immediately tell this is a risk-reporting tool and distinguish it from siblings like test_status or ready_to_merge.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives explicit triggering questions: "did my agents do anything dangerous?" or "before trusting their work." That is clear when-to-use guidance, but it names no sibling alternative and gives no when-not-to-use condition.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.