Skip to main content
Glama
amittell

firewalla-mcp-server

get_statistics_by_box

Read-only

Retrieve top Firewalla boxes by blocked flows or security alarms over the last 30 days, with box details for network monitoring and threat response.

Instructions

Top boxes by blocked flows (the default) or by Security Activity alarms, from GET /v2/stats/{type}, with each box's details from GET /v2/boxes; each box's value is the statistic, over about the last 30 days when measured. Not limited by FIREWALLA_BOX_ID.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
typeNoStatistics type to retrievetopBoxesByBlockedFlows
groupNoGet statistics for specific box group
limitNoMaximum number of results (optional, default: 5)

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint and openWorldHint, lowering the burden on the description. The description usefully adds the approximate 30-day measurement window, the fact that results are not limited by FIREWALLA_BOX_ID, and the semantics that each box's value is the statistic.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single dense sentence where every clause earns its place: default vs. alternative statistic, source endpoints, value semantics, time window, and scope limitation. No filler or redundant restatement of the tool name.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a read-only list tool with three optional parameters and no output schema, the description gives enough to invoke it correctly and interpret the result concept. It could be slightly more explicit about the exact response shape, but the endpoint references and value semantics largely compensate.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents type, group, and limit. The description reinforces the default type and the two allowed enum values, but does not add meaningful parameter-level details beyond what the schema provides.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific purpose: top boxes ranked by blocked flows or Security Activity alarms, sourced from a specific endpoint and enriched with box details. It also distinguishes this from other statistics tools by emphasizing per-box scope and the 'Not limited by FIREWALLA_BOX_ID' qualifier.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description clarifies the default statistic type and that the tool is not limited by FIREWALLA_BOX_ID, giving some usage context. However, it does not explicitly say when to prefer this tool over siblings like get_statistics_by_region or get_simple_statistics, nor does it state any exclusions.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.