Skip to main content
Glama

ECC overview

ecc_overview
Read-onlyIdempotent

Summarize Saudi NCA ECC-2:2024: four domains, subdomain and control counts, official sources. Use this overview to begin ECC compliance or reference work.

Instructions

Summary of the NCA Essential Cybersecurity Controls (ECC-2:2024): the four domains, counts of subdomains and controls, and the official sources. Start here.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
langNoLanguage for summaries and names: en or ar.en
response_formatNomarkdown for reading, json for further processing.markdown

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv1.0.0

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint, idempotentHint, non-destructive, and closed-world, so the safety profile is covered. The description adds useful context on the payload contents (four domains, counts, sources), giving the agent a sense of what a summary returns beyond a bare lookup.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two tight sentences: the first enumerates the content, the second is a one-line routing cue. No filler and the key detail is front-loaded.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a read-only, no-required-param overview tool with no output schema, the description adequately conveys scope and content. Nothing critical is missing, though a note on how it relates to the list/search siblings would make it fully self-sufficient.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% and both parameters (lang, response_format) are fully documented with enum values, so the schema does the heavy lifting. The description adds nothing about language or output format selection, so the baseline of 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific resource (the ECC-2:2024 framework overview) and enumerates what it covers: the four domains, subdomain/control counts, and official sources. It is clearly distinct from listing or search siblings, though it doesn't name them directly.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

'Start here' gives clear positioning as the entry-point tool for the ECC family, which is real usage guidance relative to siblings like ecc_list_domains or ecc_search_controls. It does not spell out when NOT to use it or name alternatives explicitly.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.