Skip to main content
Glama

List control areas

corf_list_areas
Read-onlyIdempotent

List control areas with own-words summaries and control counts, filtered by baseline, domain, or sub-domain, with paging and bilingual output.

Instructions

Control areas with their own-words summary and control counts. Limit to a baseline, a domain id ("orb:6") or a sub-domain id ("crb:5.6"). Paged.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
langNoLanguage for titles and summaries: en or ar.en
limitNoMaximum items to return.
domainNo
offsetNoItems to skip, for paging.
baselineNoBaseline: crb (Cyber Resilience), orb (Operational Resilience) or tprm (Third-Party Risk Management).
subdomainNo
response_formatNomarkdown for reading, json for further processing.markdown

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv1.0.0

TDQS

A3.6/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnly/idempotent/non-destructive, so the safety profile is covered. The description adds two pieces of real behavioral context – that results are paged and the exact filter-id shapes ('orb:6', 'crb:5.6') – but says nothing about ordering, paging limits, or what an empty result means.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three short, front-loaded sentences with no filler: content, filters, paging. It is terse almost to a fault, but every sentence carries information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description correctly previews the return shape (own-words summary plus control counts) and covers filtering and paging for a simple read-only tool. Minor gaps are return ordering and the interaction between baseline/domain/subdomain filters, which an agent may have to infer.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 71%, and the two undocumented parameters (domain, subdomain) are precisely the ones the description compensates for by giving concrete id formats ('orb:6', 'crb:5.6'). 'Paged' also maps to the offset/limit pair. lang and response_format remain schema-only, which is acceptable.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (list) and resource (control areas) and says what each item contains: an own-words summary and control counts. It is distinguishable from corf_list_domains / corf_list_subdomains, though it never explicitly names those siblings to sharpen the boundary.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives usable filtering context ('Limit to a baseline, a domain id or a sub-domain id') which tells the agent how to narrow results, but it never says when to pick this over corf_list_domains, corf_list_subdomains or corf_get_area. Usage is implied rather than contrasted against alternatives.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.