Skip to main content
Glama
ark-forge

eu-ai-act-scanner

by ark-forge

generate_annex4_package

Generate a complete Annex IV evidence package for high-risk AI audits. Automatically populates all mandatory sections from a project scan, adds SHA-256 integrity hash, and supports optional Trust Layer signing.

Instructions

Build the Annex IV evidence package your auditor needs for high-risk AI — no arguments. All 8 mandatory sections auto-populated from your project scan, SHA-256 integrity hash included. High-risk rules apply Aug 2026. Pro plan required.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
project_pathNoPath to the project root. Leave empty or pass '.' to scan the current directory..
trust_layer_keyNoArkForge Trust Layer API key. Required if sign_with_trust_layer is True.
sign_with_trust_layerNoCertify the package via Trust Layer for Art. 12 audit trail.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv1.5.0

TDQS

B3.3/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description must carry the burden of behavioral disclosure. It does mention the SHA-256 hash, Pro plan requirement, and auto-population, but it misleadingly claims 'no arguments' while the schema defines three optional parameters. It also fails to state side effects, prerequisites like a prior project scan, or output location.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is efficiently structured into three concise sentences, with the core action front-loaded. Each clause adds relevant context (audience, auto-population, integrity hash, compliance date, plan requirement). The only minor flaw is the misleading 'no arguments' phrase, which costs a point.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description gives a high-level overview of purpose and constraints but omits operational details such as where the package is saved, what file format is produced, and whether a previous scan_project call is required. With no output schema and no annotations, these gaps leave the agent without complete invocation context.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema provides full descriptions for all three parameters, which would normally warrant a baseline of 3. However, the description's 'no arguments' statement actively contradicts and muddies the schema, adding no value and potentially confusing users into thinking parameters don't exist.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb and resource: 'Build the Annex IV evidence package' and immediately identifies the audience ('your auditor') and the context ('high-risk AI'). It also highlights the deliverable's 8 mandatory sections, distinguishing it from sibling compliance and reporting tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage for high-risk AI audits and notes the Aug 2026 applicability, giving context for when the tool is relevant. However, it does not explicitly state when not to use it or mention alternatives like check_compliance or generate_report, so it lacks explicit exclusions and alternatives.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.