Skip to main content
Glama
antonio-mello-ai

io.github.antonio-mello-ai/mcp-pfsense

add_firewall_rule

Create a staged firewall rule to pass, block, or reject traffic, then apply changes to activate it.

Instructions

Add a firewall rule. Type is 'pass', 'block', or 'reject'.

The rule is staged (not active) until apply_changes('firewall') is called or apply=true is passed here.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
typeYes
applyNo
descrNo
sourceNoany
dstportNo
protocolNo
interfaceYes
ipprotocolNoinet
destinationNoany

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changedv0.3.0
    • addedInput schema / properties / apply
      Added value: +{
      +  "default": false,
      +  "title": "Apply",
      +  "type": "boolean"
      +}
  2. First observedv0.1.1

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the behavioral disclosure burden. It reveals a critical non-obvious behavior: the rule is staged, not active, until committed via apply_changes or apply=true. It does not disclose other effects like rule ordering or validation, but the most important mutation behavior is covered.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is short, front-loaded, and every sentence earns its place. It states the essential purpose, the allowed values, and the crucial staging behavior without repetition or fluff.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description covers the core call semantics and staging behavior, and the presence of an output schema reduces the need to document return values. However, most parameters remain semantically unexplained, so an agent may struggle to construct correct non-trivial rules involving protocols, ports, or interfaces.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must compensate, but it only explains the type values and apply behavior. The meanings and formats of source, destination, protocol, dstport, interface, ipprotocol, and descr are left undocumented. This is insufficient for a 9-parameter tool.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly identifies the action: 'Add a firewall rule' with a concrete resource and enumerates the valid type values. This is distinct from sibling tools like delete_firewall_rule and list_firewall_rules, and the staging note separates it from apply_changes.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives clear context for when the rule takes effect and explicitly references apply_changes('firewall') and the apply=true alternative. It does not spell out when to avoid this tool or choose a sibling, but the staging vs. immediate-apply distinction is practical guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.