Skip to main content
Glama

Assess Cloud Change Bundle

assess_cloud_change_bundle
Read-onlyIdempotent

Correlate evidence across Terraform, IAM, Kubernetes, and GitHub Actions to produce one deployment-risk assessment and identify cross-domain change paths.

Instructions

Correlate evidence from at least two domains (Terraform, IAM, Kubernetes, GitHub Actions) into one deployment-risk assessment and identify cross-domain change paths. Use domain-specific review tools when only one evidence domain is available. It analyzes caller-supplied artifacts only and does not query providers, clusters, GitHub, or deploy changes.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
terraformNoOptional Terraform evidence domain. Supply this plus at least one other domain for cross-domain assessment.
changeNameYesName or identifier for the cloud change bundle being assessed.
environmentYesTarget deployment environment; production increases the consequence of correlated risk.
iamPoliciesNoOptional IAM evidence domain with up to 10 policies; combine with at least one other domain.
githubWorkflowsNoOptional GitHub Actions evidence domain with up to 10 workflows; combine with at least one other domain.
kubernetesWorkloadsNoOptional Kubernetes evidence domain with up to 10 workloads; combine with at least one other domain.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
changeNameYes
changePathsYes
environmentYes
releaseGateYes
baseRiskScoreYes
domainSummaryYes
uncertaintiesYes
bundleRiskLevelYes
bundleRiskScoreYes
suppliedDomainsYes
correlatedFindingsYes
recommendedActionsYes
assessmentConfidenceYes
correlationAdjustmentYes
correlatedFindingCountYes
environmentRiskAdjustmentYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed45 schema fields changedv0.14.0
    • addedInput schema / properties / changeName / description
      Added value: +"Name or identifier for the cloud change bundle being assessed."
    • addedInput schema / properties / environment / description
      Added value: +"Target deployment environment; production increases the consequence of correlated risk."
    • addedInput schema / properties / githubWorkflows / description
      Added value: +"Optional GitHub Actions evidence domain with up to 10 workflows; combine with at least one other domain."
    • addedInput schema / properties / githubWorkflows / items / properties / deploysToProduction / description
      Added value: +"Whether the workflow can deploy changes to production."
    • addedInput schema / properties / githubWorkflows / items / properties / hasConcurrencyControl / description
      Added value: +"Whether concurrency settings prevent overlapping or conflicting deployment runs."
    • addedInput schema / properties / githubWorkflows / items / properties / hasDependencyCaching / description
      Added value: +"Whether dependency caching is configured for repeatable efficient builds."
    • addedInput schema / properties / githubWorkflows / items / properties / hasEnvironmentProtection / description
      Added value: +"Whether protected GitHub environments or equivalent approval controls guard deployments."
    • addedInput schema / properties / githubWorkflows / items / properties / hasLeastPrivilegePermissions / description
      Added value: +"Whether GITHUB_TOKEN permissions are explicitly restricted to least privilege."
    • addedInput schema / properties / githubWorkflows / items / properties / hasSecretScanning / description
      Added value: +"Whether the delivery process includes secret-detection controls."
    • addedInput schema / properties / githubWorkflows / items / properties / triggers / description
      Added value: +"Workflow trigger events when raw workflow YAML is not supplied."
    • addedInput schema / properties / githubWorkflows / items / properties / usesPinnedActions / description
      Added value: +"Whether third-party actions are pinned to immutable commit SHAs."
    • addedInput schema / properties / githubWorkflows / items / properties / workflowName / description
      Added value: +"Name of the GitHub Actions workflow represented by this evidence item."
    • addedInput schema / properties / githubWorkflows / items / properties / workflowYaml / description
      Added value: +"Optional raw GitHub Actions workflow YAML used to derive CI/CD evidence."
    • addedInput schema / properties / iamPolicies / description
      Added value: +"Optional IAM evidence domain with up to 10 policies; combine with at least one other domain."
    • addedInput schema / properties / iamPolicies / items / properties / actions / description
      Added value: +"Explicit IAM actions when raw policy JSON is not supplied."
    • addedInput schema / properties / iamPolicies / items / properties / allowsPrivilegeEscalationActions / description
      Added value: +"Whether the policy permits actions commonly associated with privilege escalation."
    • addedInput schema / properties / iamPolicies / items / properties / hasConditionBlocks / description
      Added value: +"Whether policy statements include IAM Condition constraints."
    • addedInput schema / properties / iamPolicies / items / properties / hasWildcardActions / description
      Added value: +"Whether the policy allows wildcard actions such as * or service:* patterns."
    • addedInput schema / properties / iamPolicies / items / properties / hasWildcardResources / description
      Added value: +"Whether the policy grants access to wildcard resources."
    • addedInput schema / properties / iamPolicies / items / properties / policyJson / description
      Added value: +"Optional raw AWS IAM policy JSON used to derive identity-risk evidence."
    • addedInput schema / properties / iamPolicies / items / properties / policyName / description
      Added value: +"Name of the IAM policy represented by this evidence item."
    • addedInput schema / properties / iamPolicies / items / properties / resources / description
      Added value: +"Explicit IAM resource ARNs or resource patterns when raw policy JSON is not supplied."
    • addedInput schema / properties / iamPolicies / items / properties / usedByProduction / description
      Added value: +"Whether the policy is attached to or used by production workloads or identities."
    • addedInput schema / properties / kubernetesWorkloads / description
      Added value: +"Optional Kubernetes evidence domain with up to 10 workloads; combine with at least one other domain."
    • addedInput schema / properties / kubernetesWorkloads / items / properties / exposesPublicService / description
      Added value: +"Whether the workload is exposed through a public Service or ingress path."
    • addedInput schema / properties / kubernetesWorkloads / items / properties / hasLivenessProbe / description
      Added value: +"Whether workload containers define liveness probes."
    • addedInput schema / properties / kubernetesWorkloads / items / properties / hasPodDisruptionBudget / description
      Added value: +"Whether disruption protection is provided by a PodDisruptionBudget."
    • addedInput schema / properties / kubernetesWorkloads / items / properties / hasReadinessProbe / description
      Added value: +"Whether workload containers define readiness probes."
    • addedInput schema / properties / kubernetesWorkloads / items / properties / hasResourceLimits / description
      Added value: +"Whether workload containers define CPU or memory limits."
    • addedInput schema / properties / kubernetesWorkloads / items / properties / hasResourceRequests / description
      Added value: +"Whether workload containers define CPU or memory requests."
    • addedInput schema / properties / kubernetesWorkloads / items / properties / manifestYaml / description
      Added value: +"Optional raw Kubernetes YAML used to derive workload evidence."
    • addedInput schema / properties / kubernetesWorkloads / items / properties / namespace / description
      Added value: +"Kubernetes namespace containing the workload."
    • addedInput schema / properties / kubernetesWorkloads / items / properties / replicas / description
      Added value: +"Configured replica count used for availability assessment."
    • addedInput schema / properties / kubernetesWorkloads / items / properties / runsAsRoot / description
      Added value: +"Whether the workload is configured to run containers as root."
    • addedInput schema / properties / kubernetesWorkloads / items / properties / usesLatestTag / description
      Added value: +"Whether any workload image uses the mutable latest tag."
    • addedInput schema / properties / kubernetesWorkloads / items / properties / workloadName / description
      Added value: +"Kubernetes workload name when raw manifest YAML is not the only identifier."
    • addedInput schema / properties / terraform / description
      Added value: +"Optional Terraform evidence domain. Supply this plus at least one other domain for cross-domain assessment."
    • addedInput schema / properties / terraform / properties / changedResources / description
      Added value: +"Terraform resource classes changed when raw plan JSON is not supplied."
    • addedInput schema / properties / terraform / properties / hasPeerReview / description
      Added value: +"Whether the Terraform change has peer-review evidence."
    • addedInput schema / properties / terraform / properties / hasRollbackPlan / description
      Added value: +"Whether the Terraform change has a documented rollback or recovery plan."
    • addedInput schema / properties / terraform / properties / hasTerraformPlan / description
      Added value: +"Whether a Terraform plan artifact exists and was reviewed."
    • addedInput schema / properties / terraform / properties / includesIamChanges / description
      Added value: +"Whether Terraform changes identity or access-management resources."
    • addedInput schema / properties / terraform / properties / includesPublicIngress / description
      Added value: +"Whether Terraform introduces or changes public ingress."
    • addedInput schema / properties / terraform / properties / modifiesStatefulResources / description
      Added value: +"Whether Terraform changes stateful resources such as databases or persistent storage."
    • addedInput schema / properties / terraform / properties / terraformPlanJson / description
      Added value: +"Optional raw Terraform plan JSON used to derive change evidence."
  2. First observedv0.4.0

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnly, idempotent, non-destructive operation, so the safety profile is covered. The description adds genuinely new behavioral scope: it analyzes caller-supplied artifacts only and does not query providers, clusters, GitHub, or deploy changes. That closes the open-world question for the caller, though return/report structure is left to the output schema.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences, zero waste, front-loaded with the core action and its precondition before the delegation rule and the scope limitation. Each sentence carries distinct information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a high-complexity tool with nested domains and an output schema, the description supplies the mental model (multi-domain correlation, caller-supplied only) and defers return shape to the output schema. Could be marginally better by noting the two-domain minimum applies to required vs optional inputs, but it is largely complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so every nested field (hasWildcardActions, usesPinnedActions, hasPodDisruptionBudget, etc.) is already documented. The description names the evidence domains but adds no format, cardinality, or combination semantics beyond the schema. Baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (correlate) and resource (evidence from Terraform, IAM, Kubernetes, GitHub Actions into one deployment-risk assessment) plus the secondary output (cross-domain change paths). An agent can tell it apart from the single-domain siblings like review_terraform_security or review_iam_policy without opening any schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives an explicit precondition (at least two evidence domains) and routes the agent to the alternative (domain-specific review tools) when only one domain is available. The when-to-use and when-to-delegate conditions are both spelled out.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.