Skip to main content
Glama
bx33661

Wireshark MCP

by bx33661

wireshark_detect_dns_tunnel

Read-only

Scan pcap files to detect DNS tunneling candidates: identify long query names, TXT abuse, and high subdomain fanout.

Instructions

[Security] Detect DNS tunneling candidates (long query names, TXT abuse, high subdomain fanout).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
pcap_fileYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed3 schema fields changedv2.0.0
    • removedInput schema / properties / pcap_file / title
      Removed value: -"Pcap File"
    • removedInput schema / title
      Removed value: -"wireshark_detect_dns_tunnelArguments"
    • changedOutput schema / (root)
      Previous value: -{
      -  "properties": {
      -    "result": {
      -      "title": "Result",
      -      "type": "string"
      -    }
      -  },
      -  "required": [
      -    "result"
      -  ],
      -  "title": "wireshark_detect_dns_tunnelOutput",
      -  "type": "object"
      -}New value: +null
  2. Addedv1.2.0

TDQS

B3/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already establish readOnlyHint=true and openWorldHint=false, so the safety profile is covered. The description adds value by disclosing the detection heuristics it applies, but says nothing about evidence quality (heuristic vs. confirmed), false-positive behavior, or the shape of results. With annotations carrying the safety burden, this is an adequate-but-thin 3.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single front-loaded sentence with the [Security] tag first and the detection criteria in parentheses; every clause earns its place. It is terse to the point of under-specification, but there is no wasted text.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a single-parameter detection tool with annotations covering the read-only profile, the definition is minimally complete. However, with no output schema, nothing tells the agent what the detection returns (candidate list, counts, per-domain detail), leaving a real gap for interpreting results.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

There is one parameter (pcap_file) and schema description coverage is 0%, so the description carries the full explanatory burden and does not mention the parameter at all. An agent gets no clarification on accepted formats, path expectations, or whether the file must be pre-opened with wireshark_open_file.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description gives a specific verb (Detect) and resource (DNS tunneling candidates) and enumerates the heuristics used (long query names, TXT abuse, high subdomain fanout), which makes the intent unambiguous. It does not, however, differentiate itself from nearby siblings such as wireshark_extract_dns_queries or wireshark_detect_exfiltration, so the agent must infer the boundary.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no statement of when to reach for this tool versus alternatives like detect_exfiltration, detect_beaconing, or extract_dns_queries, and no prerequisites (e.g. that a pcap_file is required) are surfaced in prose. The name and heuristics imply a use case but the description offers no explicit routing guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.