Skip to main content
Glama
YawLabs

@yawlabs/tailscale-mcp

by YawLabs

Validate AWS trust policy

tailscale_validate_aws_trust_policy
Read-onlyIdempotent

Validate that an AWS IAM role trust policy includes the correct Tailscale external ID. Use after configuring the IAM role for S3 log streaming.

Instructions

Validate that an AWS IAM role trust policy is correctly configured with the Tailscale external ID. Use this after setting up the IAM role for S3 log streaming.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
roleArnYesThe AWS IAM role ARN to validate against
externalIdYesThe AWS external ID to validate

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.13.3

TDQS

A3.8/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare this as a read-only, idempotent, non-destructive, open-world operation, so the safety profile is covered. The description adds useful workflow context by tying it to the S3 log streaming setup, but omits what the validation actually returns (pass/fail, error detail) and any auth prerequisites.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two tightly written sentences: purpose first, usage trigger second. Nothing is redundant and the key information is front-loaded.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a simple two-parameter read-only validation tool with full schema coverage and clear annotations, the description is nearly complete. The only mild gap is that it doesn't hint at the shape of the validation result, though no output schema exists.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% – both roleArn and externalId are documented in the schema itself. The description adds no syntax or format detail beyond that, so the baseline of 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (Validate) and a specific resource (AWS IAM role trust policy), plus the exact thing being checked (correct configuration with the Tailscale external ID). It's clear, though it doesn't explicitly differentiate itself from the adjacent tailscale_create_aws_external_id sibling.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

'Use this after setting up the IAM role for S3 log streaming' gives a concrete lifecycle trigger for when to invoke it. It stops short of naming alternatives or stating when not to use it, so it's clear context without full exclusion guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools