Skip to main content
Glama

Draft a notice

najjab_draft_notice
Read-onlyIdempotent

Draft a regulator-ready incident notice in Arabic or English, compiling required facts and directing it to the correct authorities, forms, and channels.

Instructions

A plain notice in Arabic or English that gathers the facts every regulator asks for first, addressed to the authorities the incident triggers. Use the authority's own form and channel where one exists.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
langNoLanguage for the answer: en or ar.en
zonesNoFinancial free zones the organization also operates in: difc and adgm (UAE), qfc (Qatar). Their data protection duties are added; federal duties still apply outside the zone.
sectorNogeneral, banking, insurance, payments, telecom, government or critical (critical infrastructure).general
actionsNo
contactNo
recordsNo
summaryNo
systemsNo
severityNoThe grade your own classification gives: critical, high, medium or low.high
countriesYesEvery country the organization operates in, for example ["KW", "SA"].
next_updateNo
organizationNo
discovered_atYesWhen the incident was discovered, ISO 8601 with offset, for example "2026-10-04T08:00:00+03:00".
incident_typeYesransomware, bec (business email compromise), data-breach or cloud-key (exposed cloud access keys).
personal_dataNoTrue when personal data was affected. A data-breach always counts as personal data.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.4.1

TDQS

B3.4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true, idempotentHint=true, destructiveHint=false and openWorldHint=false, so the agent knows this is a safe, repeatable, local generation call. The description adds useful framing (bilingual output, fact-gathering scope, authority-specific form/channel), but discloses nothing about authentication, rate limits, or the shape/size of the returned draft. No contradiction with annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two tight sentences with the deliverable front-loaded and no filler. It is efficient, though slightly abstract for a 15-parameter tool where a few more words could have disambiguated the free-text fields.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With 15 parameters, 53% schema coverage, no output schema, and seven undocumented free-text inputs, the description carries a real burden. It explains the intent and the addressee but never describes what the drafted notice contains or how the unlabeled fields feed it, leaving a meaningful gap for an agent assembling a call.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is only 53%, and the undocumented fields (actions, contact, records, summary, systems, organization, next_update) are bare strings with no guidance. The description partially compensates by framing these as "the facts every regulator asks for first," and the Arabic/English and authority mentions echo the lang and countries parameters, but it adds no syntax or format detail.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a concrete deliverable (a plain notice, in Arabic or English) that consolidates the facts regulators ask for, addressed to the authorities an incident triggers. An agent can tell this is a drafting/generation tool. It never contrasts itself with the playbook, tabletop, or deadlines siblings, so differentiation is left to inference.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

"Addressed to the authorities the incident triggers" implies the context (post-incident notification) and "use the authority's own form and channel where one exists" gives downstream usage guidance. However, no sibling alternative is named and no when-not condition is stated, so selection guidance is only implied.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.