Skip to main content
Glama
bx33661

Wireshark MCP

by bx33661

wireshark_detect_dos_attack

Read-only

Analyze packet captures to detect DoS/DDoS volume patterns, including SYN floods, ICMP/UDP floods, and DNS amplification.

Instructions

[Security] Detect DoS/DDoS traffic volume patterns (SYN flood, ICMP/UDP flood, DNS amplification).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
pcap_fileYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed3 schema fields changedv2.0.0
    • removedInput schema / properties / pcap_file / title
      Removed value: -"Pcap File"
    • removedInput schema / title
      Removed value: -"wireshark_detect_dos_attackArguments"
    • changedOutput schema / (root)
      Previous value: -{
      -  "properties": {
      -    "result": {
      -      "title": "Result",
      -      "type": "string"
      -    }
      -  },
      -  "required": [
      -    "result"
      -  ],
      -  "title": "wireshark_detect_dos_attackOutput",
      -  "type": "object"
      -}New value: +null
  2. Addedv1.2.0

TDQS

C2.8/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true and openWorldHint=false, so the agent knows this is a safe local read. The description adds nothing further: no thresholding logic, no note on false positives, no indication of whether it analyzes the whole file or a window, and no mention of what constitutes a 'pattern' hit.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single front-loaded sentence with the [Security] category tag, the verb, the resource, and parenthetical examples. Nothing is wasted, though the examples are the only thing that keeps it from being a bare name restatement.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a one-parameter read-only detector with no output schema, the definition is minimally viable but leaves the return shape unexplained — the agent cannot tell if results are a boolean, a list of anomalies, or volume statistics. It should say more about what a detection report contains.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The single parameter pcap_file has 0% schema description coverage and the description does not compensate — it never explains what the file argument should be (capture path, format, size limits). Only one parameter exists, but its semantics are left entirely implicit.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb+resource (detect DoS/DDoS traffic volume patterns) and enumerates the concrete attack signatures it targets (SYN flood, ICMP/UDP flood, DNS amplification). That clearly separates it from sibling detectors like detect_port_scan or detect_beaconing, though no sibling is named explicitly.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no guidance on when to reach for this tool versus other detect_* siblings, no prerequisites (e.g., which pcap types are supported, whether decrypted traffic is needed), and no exclusions. The agent must infer usage from the name alone.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.