Skip to main content
Glama

Export client HTTP network traffic to standard HAR (HTTP Archive) format

lol_forensics_export_har
Read-onlyIdempotent

Exports HTTP/HTTPS traffic from an active capture to HAR 1.2, redacting authorization headers, cookies, and credentials. Saves to disk or returns JSON for forensic analysis.

Instructions

Exports captured HTTP/HTTPS network traffic from the active network tailer into a standard HAR 1.2 archive. Automatically redacts sensitive authorization headers (Basic/Bearer auth, Riot auth tokens), session cookies, and credentials. If savePath is specified, writes the formatted HAR file directly to disk; otherwise returns the full HAR JSON structure. Prerequisite: Network recording must be active; call lol_cdp_network_start first to begin capturing requests.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
limitNoMaximum number of network entries to include in HAR
savePathNoOptional absolute path to write .har file to disk. If omitted, returns the HAR JSON structure.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Addedv0.6.0

TDQS

B3.3/5.0
Behavior1/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description explicitly states that, when savePath is supplied, the tool 'writes the formatted HAR file directly to disk' — a filesystem mutation (and potential overwrite of an existing file) that directly conflicts with the annotations readOnlyHint=true and destructiveHint=false. The description does add genuinely useful non-annotation context (automatic redaction of Basic/Bearer/Riot tokens, cookies and credentials), but the explicit write behavior contradicts the declared safety profile.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences, purpose front-loaded, no filler; each sentence carries information (scope, redaction, conditional I/O, prerequisite). Minor redundancy: the savePath branching restates the schema's own savePath description almost verbatim.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema present, the description correctly compensates by saying what is returned (full HAR JSON structure) and what is stripped (auth headers, cookies, credentials), and it flags the prerequisite capture state. It never explains the 'limit' parameter or entry-count implications, and the write-to-disk claim conflicts with the provided annotations.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% and the schema already documents both parameters, including savePath's conditional behavior in nearly the same words ('If omitted, returns the HAR JSON structure'). The description therefore adds no semantics beyond the schema for either parameter, and the 'limit' cap of 5000 entries is never mentioned. Baseline 3 is appropriate when the schema does the heavy lifting.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description gives a specific verb+resource ('Exports captured HTTP/HTTPS network traffic') and names the exact output artifact ('standard HAR 1.2 archive'), which is far more precise than the title alone. It anchors the source ('active network tailer') so it cannot be confused with lol_cdp_network_tail, but it never explicitly contrasts itself with the other forensics exporters (lol_forensics_bundle, lol_forensics_correlate), so full sibling differentiation is absent.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It states an explicit precondition and the tool to call first ('Network recording must be active; call lol_cdp_network_start first'), and it explains the two modes of use (disk write when savePath is given, JSON return otherwise). It stops short of naming when NOT to use it or how it relates to the other forensics export siblings.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.