csw-mcp
csw-mcp is a read-only MCP server that lets you query a Cisco Secure Workload cluster in natural language through clients like Cursor, Claude Desktop, Grok, Codex, and Gemini.
List scopes and the scope hierarchy.
Inventory agents/sensors with type, platform, and IPs.
Search inventory by IP, hostname, OS, or annotations; fetch a single workload by IP.
Summarize cluster posture: agent counts, enforcement coverage, and agent-type breakdown.
List workspaces/applications and their policies.
List policies applied to a specific workload.
Search recent network flows with filters and time windows.
List ADM conversations for a workspace.
Rank risky-service exposure to ports such as RDP, SMB, telnet, and common DB ports.
Retrieve workload CVEs with severity tallies and installed packages.
Rank the most vulnerable hosts by CVE severity.
List configured forensic profiles.
Access resources for cluster info, scopes, latest snapshots, and executive reports.
Use prompts for blast-radius triage, weekly posture review, and POV closeout.
Stay read-only with stdio transport, bounded results, and no arbitrary request escape hatch.
Read-only querying of a Cisco Secure Workload (CSW/Tetration) cluster — inspects scopes, agents/sensors and their enforcement vs. visibility mode, workspaces and policies, inventory workloads, observed network flows and ADM conversations, plus workload CVEs, installed packages and forensic profiles. Includes posture aggregators such as cluster posture KPIs, risky-service exposure ranking (RDP/SMB/telnet/DB ports), and host ranking by CVE severity.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@csw-mcphow many agents are enforcing policy?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
csw-mcp
Query Cisco Secure Workload in natural language — a read-only MCP server for Cursor, Claude Desktop, Grok, Codex, and Gemini.
Ask “how many agents are enforcing policy?” or “which hosts have exploitable critical CVEs?” — and get an answer, not an API call.
What it is
csw-mcp is a Model Context Protocol server
that lets MCP clients (Cursor, Claude Desktop, Grok, Codex, and Gemini) query a Cisco Secure Workload
(CSW / Tetration) cluster in plain English. It is for anyone who wants to
use CSW and get posture answers without writing HMAC-signed API calls.
flowchart TB
ui["1 · In the Secure Workload UI<br/>User Menu → API Keys → Create API Key"]
env["2 · On your laptop, copy .env.example to .env<br/>CSW_API_URL · CSW_API_KEY · CSW_API_SECRET"]
ask["3 · Ask in Cursor, Claude Desktop,<br/>Grok, Codex, or Gemini"]
local["4 · csw-mcp reads that .env<br/>and signs each call with the API secret"]
tenant["5 · Your Secure Workload tenant"]
reply["6 · The answer comes back in the chat"]
ui --> env --> ask --> local
local -->|"read-only, no OAuth"| tenant
tenant -->|"scopes · agents · workspaces<br/>inventory · forensic profiles"| reply
classDef step fill:#F8FAFC,stroke:#005073,color:#020617;
classDef cred fill:#FFFBEB,stroke:#d97706,color:#020617;
classDef cisco fill:#00bceb,stroke:#005073,color:#ffffff;
class ask,local,reply step;
class ui,env cred;
class tenant cisco;Where the cluster info goes: a file named .env in this repo (it stays on your machine and is never committed). No OAuth, no browser login, and no extra token service. Secure Workload uses an API key plus its matching secret. Create that pair in the product UI under User Menu → API Keys → Create API Key, then put these three lines in .env:
CSW_API_URL=https://your-cluster.tetrationcloud.com
CSW_API_KEY=your_api_key_here
CSW_API_SECRET=your_api_secret_hereCSW_API_URL is the cluster address only, with no path on the end. The key needs read access for sensors, flows, and policy. Setup steps are in docs/INSTALL.md.
Start with one of these. They are the current capabilities confirmed on a live tenant:
“Show me the scope tree.”
“List the agents on this cluster.”
“What workspaces are defined?”
“Find the workload for this IP.”
“Which forensic profiles are on this cluster?”
The server only reads. It does not create, change, or delete anything on the tenant, and it listens only on a local stdio pipe. The HMAC signing and module layout are in docs/ARCHITECTURE.md.
This repo is companion tooling, not official Cisco documentation. Confirm behavior against your cluster's in-product help and the Cisco Secure Workload product documentation.
Related MCP server: MSSQL-MCP
New to Cisco Secure Workload?
Cisco Secure Workload (also called Tetration) watches how servers talk to each other, then lets you write firewall-style rules that follow the workload instead of a fixed IP. The goal is simple: if one machine is compromised, the attacker should not be able to walk sideways to the next one. That is micro-segmentation, and the size of the damage an attacker can do is the blast radius.
You do not need to know the product to use this server. Ask a question in English. The model calls the tools below and answers in plain language.
Term you will see | Plain meaning |
Agent / sensor | Software on a host that reports connections. In enforcement mode it also blocks traffic the policy does not allow. In visibility mode it only watches. |
Scope | A folder in the inventory tree (for example Production, Databases, WebTier) used to group workloads and attach policy. |
Workspace / application | A policy container. ADM (Application Dependency Mapping) looks at real traffic and proposes a starter ruleset. |
Flow | One observed connection: who talked to whom, on which port, and whether policy allowed it. |
Conversation | A summarized "these two groups talk on this port" pair that ADM uses to draft policy. |
Workload | One host, VM, or pod that CSW is tracking. |
If you want the longer story — why this exists, how a POV is run, and a video learning path — start with CSW User Education.
Quickstart
# 1. Enter the repo
cd csw-mcp
# 2. Create the environment and install (uv — https://astral.sh/uv)
uv venv
uv pip install -e .
# 3. Configure credentials
cp .env.example .env # then edit with your cluster URL / key / secret
# 4. Register with Cursor (idempotent)
bash scripts/install-cursor.sh
# 5. Restart Cursor, then ask: "Summarize my CSW cluster posture."Verify it loaded:
uv run python -c "from csw_mcp.server import mcp; print('tools:', len(mcp._tool_manager._tools), 'prompts:', len(mcp._prompt_manager._prompts))"
# tools: 15 prompts: 3
# Optional: smoke-test every tool against your own cluster
uv run python tests/test_tools_live.pyFull step-by-step with screenshots-as-ascii: docs/INSTALL.md.
Capabilities
Tools (15)
Name | What it does |
| List the scope hierarchy ( |
| List agents/sensors (uuid, hostname, agent_type, platform, IPs) |
| Search inventory by field/value filter |
| Fetch one workload's inventory record by IP |
| Headline posture KPIs (enforcement coverage, agents by type) |
| List application workspaces (policy folders / ADM scopes) |
| List policies defined in a workspace |
| List policies currently applied to a workload |
| Search network flows over a recent time window |
| List ADM conversations (talker pairs) for a workspace |
| Rank risky-service exposure (RDP/SMB/telnet/DB ports) |
| List CVEs on a workload + severity tally |
| List installed packages on a workload |
| Rank hosts by CVE severity (critical×10 + high) |
| List configured forensic profiles |
Resources (4)
URI | What it does |
| Cluster URL, config state, quick scope/agent counts |
| Scope hierarchy (cached ~60s) |
| Newest local |
| Newest local executive-summary markdown |
Prompts (3)
csw/triage-blast-radius · csw/weekly-posture-review · csw/pov-closeout
See docs/USAGE.md for example prompts and when to use each tool.
Current capabilities
Confirmed on a live SaaS tenant. Each row below returned data. Full notes: docs/TESTED.md.
Feature | What you get | Try this | |
✅ |
| The scope tree | “Show me the scope tree.” |
✅ |
| Agents, hostnames, platforms, addresses | “List the agents on this cluster.” |
✅ |
| Application workspaces | “What workspaces are defined?” |
✅ |
| Inventory matches for an IP or field | “Find the workload for this IP.” |
✅ |
| One workload record | “Show me the workload at this IP.” |
✅ |
| Configured forensic profiles | “Which forensic profiles are on this cluster?” |
✅ |
| Agent count, scope count, and enforcement coverage | “How many agents are enforcing?” |
✅ |
| Absolute and default policies for a workspace | “Show the policies in this workspace.” |
✅ |
| Recent flows in a scope | “Show recent flows in the root scope.” |
✅ |
| ADM conversations for a workspace | “Show the conversations for this workspace.” |
✅ |
| Risky ports with recent flow activity | “Which risky ports have recent traffic?” |
Examples
Five fully-synthetic walkthroughs live in examples/, each with
a question, the tool-call flow, and a rendered HTML deliverable:
blast-radius-triage— "Which hosts aren't enforcing?"executive-summary— "One-page CISO summary."cve-prioritization— "Exploitable + exposed CVEs?"weekly-posture-review— "What changed since last week?"pov-closeout— "Closeout + 30-day plan."
Configuration
Credentials come from a project-level .env (never committed — see .gitignore):
Variable | Required | Notes |
| yes | Cluster base URL, no trailing slash |
| yes | API key (hex) from CSW UI → API Keys |
| yes | HMAC signing secret paired with the key |
| no | Set |
| no | Explicit path to an alternate env file |
| no | Path to a CSW_POV_Template checkout (enables snapshot/report resources) |
Generate an API key in the CSW UI (User Menu → API Keys → Create API Key) with
read capabilities: sensor_management, flow_inventory_query, app_policy_management.
Safety & design principles
Read-only. Only GET and read-only search POSTs; no create/update/delete tools.
stdio transport. No listening socket → no DNS-rebinding / CSRF surface.
Single-purpose tools. No "run arbitrary request" escape hatch.
Bounded. Result limits are clamped; aggregators cap fan-out and pagination.
No secrets in code. Credentials load from a git-ignored
.env; nothing is logged.Minimal output. Tool results are projected to the fields you need.
More detail: docs/ARCHITECTURE.md.
Documentation
Doc | Contents |
Full install, wiring, verification | |
Example prompts, tool selection, combining tools | |
Top 10 "it broke" fixes | |
How to add a new tool (+ test) | |
Components, modules, HMAC auth flow |
Development
The CSW API client (src/csw_mcp/vendor/csw_api.py, csw_helpers.py) is
vendored from the generic CSW_POV_Template project and should not be edited
by hand. Re-sync it with:
CSW_POV_TEMPLATE=/path/to/CSW_POV_Template bash scripts/sync-vendor.shRegenerate the example reports:
python3 examples/build_examples.pyRelated CSW material
Same author, public repos. Use these when you want the background, a POV plan, or the script toolkit this server sits on top of. Customer-specific repos are intentionally not listed here.
Learn the product
Repo | Use it when you want… |
A plain-language intro, video library, and onboarding path | |
A field guide any SE can run: scope, observe, model policy, enforce safely, executive readout | |
Who shows up in a deal, what they care about, and which CSW topics to lead with | |
Official Secure Workload documentation |
Query and report on a cluster
Repo | How it relates to csw-mcp |
The Python scripts (snapshots, flows, policies, HTML reports) whose API client this server vendors. Use the scripts for batch reports; use csw-mcp to ask questions in chat. | |
Reads an agent diagnostic log bundle (enforcement timing, policy versions) — a different input than the live API this server calls. | |
How CSW controls map to HIPAA, SOC 2, PCI DSS, NIST 800-53, ISO 27001, and related frameworks | |
A visual companion to the |
Install agents and connect other systems
Repo | Topic |
Install the agent on cluster nodes and enforce pod/service policy | |
Connector labels, DaemonSet, container CVE scanning | |
Same pattern, plus the privileged SCC OpenShift requires | |
Deploy the on-prem virtual cluster (OVA, site config, hardening) | |
Host policy plus firewall (NSEL) visibility | |
Inventory enrichment labels from ServiceNow | |
Align CSW scopes with ACI EPGs |
License
Available Tools
15 toolsget_conversationsA
List ADM conversations (observed talker pairs) for a workspace.
Args:
app_id: The workspace/application id (from list_workspaces).
version: Optional ADM version; omit for the latest.
Reads GET /openapi/v1/conversations/{app_id}, paginating up to a safety cap.
Conversations are the raw src→dst:port pairs ADM used to propose policy.
| Name | Required | Description | Default |
|---|---|---|---|
| app_id | Yes | ||
| version | No |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the burden and does useful work: it discloses the underlying HTTP verb (GET /openapi/v1/conversations/{app_id}), identifies the call as a read, and warns that it paginates 'up to a safety cap'. It stops short of stating auth needs or what happens at the cap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loads the purpose in one line, then parameter meanings, then behavioral notes about the endpoint and pagination. Well-organized with no filler, though the Args block slightly restates what the parameter list already implies.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need not be described. Given the low-complexity two-parameter read, the description covers purpose, parameters, read-only nature, and pagination behavior adequately; only auth/truncation semantics are left implicit.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, so the description must compensate and largely does: app_id is explained as the workspace/application id sourced from list_workspaces, and version is explained as optional with 'omit for the latest'. It could say more about the version value's meaning, but both parameters are given usable semantics.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (List) and resource (ADM conversations / observed talker pairs) scoped to a workspace. The parenthetical 'raw src→dst:port pairs ADM used to propose policy' distinguishes it from sibling flow-search tools like search_flows and top_risky_flows without needing their schemas.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is implied by the resource ('conversations for a workspace') and it helpfully points to list_workspaces as the source of app_id. However, it never states when to choose this over search_flows or other inventory/flow tools, and gives no exclusions.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_workloadA
Fetch the inventory record for a single workload by IP address.
Looks up the workload via a read-only inventory search for the exact IP. Returns the full record if found, or a graceful not-found message. Use this to inspect one host's annotations, scopes, and attributes.
| Name | Required | Description | Default |
|---|---|---|---|
| address | Yes |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations supplied, the description carries the full behavioral burden and does disclose two meaningful traits: the lookup is read-only (no mutation risk) and a missing host returns a graceful not-found message rather than an error. It omits permission/auth requirements and rate limits, which keeps it short of a 5.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three short sentences, front-loaded with the core action and ending with the intended use. Slight redundancy between 'Fetch the inventory record' and 'Looks up the workload via a read-only inventory search' costs it a perfect score.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a single-parameter read tool with an output schema available to describe return shape, the description covers action, scope, safety, and failure behavior. Nothing an agent needs in order to invoke it correctly is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 0% and the lone 'address' parameter has no schema description, but the description compensates by specifying that the value is an IP address and that the match must be exact. That is the key semantics an agent needs for a single required string argument.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (fetch/look up), resource (inventory record for a single workload) and scope (by exact IP address). It implicitly separates itself from the sibling 'search_inventory' by emphasizing 'a single workload' and 'the exact IP', though it never names an alternative tool outright.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
'Use this to inspect one host's annotations, scopes, and attributes' gives clear context for when the tool applies. There are no explicit exclusions or named alternatives, so an agent must infer that bulk queries belong to search_inventory.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_workload_cvesA
List CVEs / vulnerabilities detected on a single workload.
Args:
uuid: The workload/sensor UUID (from list_sensors).
Returns records from GET /openapi/v1/workload/{uuid}/vulnerabilities plus a
severity tally (critical/high/medium/low).
| Name | Required | Description | Default |
|---|---|---|---|
| uuid | Yes |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden. It does disclose that this is a read operation via the underlying 'GET /openapi/v1/workload/{uuid}/vulnerabilities' endpoint and that results include a severity tally (critical/high/medium/low), which adds real behavioral context. It says nothing about pagination, result limits, or permissions, so gaps remain.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded with the core purpose in one sentence, followed by tightly scoped Args and Returns notes. Every line earns its place; the only minor overhead is the docstring-style formatting.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given a single required parameter and an existing output schema, the definition supplies what an agent needs: purpose, parameter provenance, and return-shape hint. Minor omissions around pagination and access requirements keep it short of complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, so the description must compensate for the single parameter, and it does: it identifies `uuid` as the workload/sensor UUID and points to `list_sensors` as the source. This adds provenance beyond the bare 'string' type, though it doesn't specify format or validation.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('List CVEs / vulnerabilities') with explicit scope ('on a single workload'). An agent can distinguish it from inventory-oriented siblings like get_workload_packages or the aggregate top_vulnerable_hosts, though no sibling is named directly.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The Args note gives useful provenance for the required parameter ('from `list_sensors`'), which tells the agent where to obtain input. However, there is no explicit when-to-use guidance relative to alternatives such as top_vulnerable_hosts, and no stated prerequisites or exclusions.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_workload_packagesA
List installed software packages on a single workload.
Args:
uuid: The workload/sensor UUID (from list_sensors).
Returns records from GET /openapi/v1/workload/{uuid}/packages.
| Name | Required | Description | Default |
|---|---|---|---|
| uuid | Yes |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full disclosure burden. "List" implies a read-only operation and it discloses the underlying endpoint, but it says nothing about pagination, result limits, or permissions required to enumerate packages on a host. Adequate but incomplete for a no-annotation tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded with the purpose, then a short Args block and a return-source line. Every sentence carries information; the endpoint disclosure is mildly redundant with the description's first sentence but not wasteful.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return-format explanation is unnecessary, and the single required parameter is documented both in prose and sourcing. For a simple read-only list call, what remains missing (pagination/limits) is minor.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 0% — the schema only declares a bare string named "uuid" — so the description must compensate, and it does: it explains that the parameter is the workload/sensor UUID and that it comes from `list_sensors`. The only gap is that it does not clarify the accepted UUID format.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ("List installed software packages on a single workload"), which is clearly distinct from siblings like get_workload_cves or get_workload. It does not explicitly contrast itself with search_inventory, the closest alternative, but the scope word "single workload" already narrows intent.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage via the singular-workload scope and tells the agent where the uuid comes from (`list_sensors`), which is genuinely useful routing information. However, it never states when to use this instead of search_inventory or other inventory tools, nor any prerequisites.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_workspace_policiesA
List the policies defined in a workspace.
Args:
app_id: The workspace/application id (from list_workspaces).
Returns the policy records from
GET /openapi/v1/applications/{app_id}/policies.
| Name | Required | Description | Default |
|---|---|---|---|
| app_id | Yes |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden. It discloses the underlying endpoint (GET /openapi/v1/applications/{app_id}/policies), which signals a safe read, but says nothing about auth requirements, pagination, result caps, or whether the list is complete or filtered.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded purpose sentence, then a compact Args note and a return line. Mildly redundant to restate the return records when an output schema already exists, but nothing is padded.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a one-parameter read tool with an output schema, the description covers purpose, the single argument, and its source. The remaining gap is routing guidance against the near-identical sibling list_policies_for_workload, which the description never addresses.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, so the description must compensate, and it does: app_id is explained as the 'workspace/application id' plus where to obtain it (list_workspaces). That is meaningfully more than the bare 'App Id' title in the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('List the policies defined in a workspace'), and the workspace scope implicitly separates it from the sibling list_policies_for_workload. It stops short of naming that sibling explicitly, so an agent must infer the boundary from scope alone.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is only implied — clearly a read for a given workspace — and the description never states when to prefer it over list_policies_for_workload or list_policies_for_workload. The one useful nudge is the provenance hint that app_id comes 'from `list_workspaces`', which chains the tool correctly.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_forensic_profilesB
List configured forensic profiles (behavioral rule sets for agents).
Returns records from GET /openapi/v1/inventory_config/forensic_profiles.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden. Naming the underlying GET endpoint implies a read-only, non-mutating call, which is useful signal, but it says nothing about pagination, permissions, filtering, or result volume.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two short sentences, front-loaded with the purpose. The second sentence is partly redundant metadata but does convey read-only semantics via the HTTP verb.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need not be described, and there are no parameters to document. The only meaningful gap is the absence of explicit read-only/pagination context for an unannotated tool, which is minor.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool takes zero parameters and the schema has no properties, so there is nothing for the description to disambiguate; baseline 4 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb+resource ('List configured forensic profiles') and adds a clarifying gloss that they are 'behavioral rule sets for agents'. It does not explicitly differentiate itself from siblings like list_scopes or list_sensors, but the resource noun is distinct enough to identify it.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
There is no guidance on when to call this versus alternatives, nor any prerequisite or context conditions. The reader must infer usage entirely from the resource name.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_policies_for_workloadA
List the policies that currently apply to a single workload.
Args:
uuid: The workload/sensor UUID (from list_sensors).
Returns the policies from GET /openapi/v1/workload/{uuid}/policies — useful
to understand exactly what a given host is allowed to talk to.
| Name | Required | Description | Default |
|---|---|---|---|
| uuid | Yes |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden. It discloses that this is a read against GET /openapi/v1/workload/{uuid}/policies and identifies the data source, but says nothing about pagination, permissions, or result shape. Adequate but not rich for an unannotated tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded purpose sentence followed by a scoped args block and a short rationale. Slightly verbose around the endpoint sentence, but each line carries information without waste.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need not be spelled out, and the description still names the underlying endpoint and the practical intent. For a single-parameter read tool this is close to sufficient, with only permissions/pagination details absent.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 0% and there is one parameter, so the description must compensate. It does: 'uuid: The workload/sensor UUID (from list_sensors)' tells the agent what the value is and where to obtain it, which is more than the schema offers.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource with clear scope ('policies that currently apply to a single workload'), which distinguishes it from the workspace-level sibling get_workspace_policies. It stops short of explicitly naming that sibling, but the workload-vs-workspace scope is unambiguous.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is implied by 'useful to understand exactly what a given host is allowed to talk to' and by pointing to list_sensors as the source of the uuid. There is no explicit when-not guidance or named alternative tool.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_scopesA
List the CSW scopes (the hierarchy that organizes workloads and policy).
Returns a count and the raw scope records from GET /openapi/v1/app_scopes.
Use this to understand how the cluster is segmented before drilling in.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden. It discloses useful behavioral detail: the tool is a read ('List'), returns a count plus raw records, and maps to GET /openapi/v1/app_scopes. It does not state whether the list is paginated, complete, or what permissions/authentication are required, leaving gaps for a no-annotation tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three short sentences, front-loaded with the resource and its meaning, followed by return shape and usage context. Every sentence adds value with no redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so the description need not detail return values, though it helpfully summarizes them. For a zero-parameter read tool this covers purpose, usage, and output. Pagination and completeness of the listing are the only minor omissions.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool takes zero parameters and schema coverage is 100%, so there are no parameter semantics to explain and the baseline is 4.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description gives a specific verb+resource ('List the CSW scopes') and defines the resource's role ('the hierarchy that organizes workloads and policy'), so an agent can tell it is enumerating cluster segmentation structures. It does not explicitly contrast with siblings like list_workspaces or list_sensors, so it stops short of full sibling differentiation.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
'Use this to understand how the cluster is segmented before drilling in' supplies a clear usage context and sequencing hint. However, no alternative tool is named and no exclusions or prerequisites are stated, so the guidance remains implied rather than explicit.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_sensorsA
List the agents/sensors registered on the cluster (summarized).
Each entry includes uuid, hostname, agent_type (ENFORCER / VISIBILITY / …),
platform, and the host's IPs. limit caps how many records are returned
(1–1000). Use this to inventory the fleet and spot which hosts run an
enforcing agent vs. visibility-only.
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations, so the description carries the full behavioral burden. It discloses that results are summarized and enumerates returned fields, but says nothing about permissions, pagination, or what happens when the fleet exceeds the limit ceiling — gaps that matter for a list tool with zero annotation coverage.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded with the purpose, then the returned-field summary and the limit semantics. Every sentence carries information; the only mild redundancy is listing return fields when an output schema already exists.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With an output schema present, the description need not explain return values yet still does so helpfully. For a single-parameter read tool with no annotations, the coverage of purpose, fields, and limit range makes it adequately complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 0%, so the description must compensate, and it does: 'limit caps how many records are returned (1–1000).' That supplies both meaning and the valid range the schema lacks, though the default of 100 is left unmentioned.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('List the agents/sensors registered on the cluster') plus scope ('summarized'), so the operation is unambiguous. It does not name or contrast itself with siblings like search_inventory or summarize_cluster_posture, which is the only thing keeping it from a 5.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly says what the tool is for: 'Use this to inventory the fleet and spot which hosts run an enforcing agent vs. visibility-only.' That is a clear usage context, but it offers no exclusions or pointer to alternatives for filtered/targeted queries.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_workspacesA
List application workspaces (policy folders / ADM scopes).
Returns the workspaces from GET /openapi/v1/applications. Each workspace
groups policy rules and ADM versions. Use the returned id with
get_workspace_policies or get_conversations.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the burden. It discloses the underlying endpoint (GET /openapi/v1/applications), states what is returned (the workspaces), and explains the grouping semantics of the resource. For a zero-parameter read-only list this is solid; it lacks only pagination/size hints, a minor gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three tight sentences, front-loaded with the noun phrase and its disambiguation, then the endpoint, then the follow-up tool routing. Nothing is padding; every sentence adds usable information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return-value detail is not the description's job, and the description still volunteers the useful `id`-based follow-up. The only omission is a contrast with the sibling list_scopes, which would fully close the loop on selection.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool takes zero parameters, which sets the baseline at 4. The description correctly adds no parameter detail because none exists, and the empty schema is fully consistent with a parameterless lister.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Specific verb+resource ('List application workspaces') with a clarifying gloss ('policy folders / ADM scopes') and a note on what each workspace groups. An agent can distinguish this from siblings like list_scopes or list_policies_for_workload without opening the schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly routes the agent onward: use the returned `id` with `get_workspace_policies` or `get_conversations`. That cleanly describes downstream usage. It does not, however, say when to prefer this over the similar-sounding `list_scopes` sibling, so it falls short of a full when/when-not treatment.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
search_flowsA
Search network flows over a recent time window.
Args: filter_json: A CSW flow filter as a JSON string, e.g. '{"type":"eq","field":"dst_port","value":3389}'. Pass an empty string for no filter (all flows in the window). hours: Look-back window in hours (1–720, default 24). limit: Max flow records to return (1–1000).
Runs a read-only POST /openapi/v1/flowsearch with t0 = now-hours, t1 = now.
| Name | Required | Description | Default |
|---|---|---|---|
| hours | No | ||
| limit | No | ||
| filter_json | No |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations present, the description carries the full burden and does disclose the key behavioral trait: it "Runs a read-only POST /openapi/v1/flowsearch with t0 = now-hours, t1 = now." This tells the agent the operation is non-mutating and how the time window is computed. It omits auth requirements and any rate/result-size caveats.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded purpose sentence, then a clean Args block, then one line of implementation detail. Every element earns its place, though the trailing endpoint description is somewhat module-specific rather than agent-facing.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Because an output schema exists, return values need not be described, and all three parameters are documented with ranges and an example. The remaining gap is the absence of auth/permission context or pagination behavior for a tool that can return up to 1000 records.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, yet the description compensates fully: it gives a concrete filter JSON example with field syntax, the empty-string default meaning, valid ranges for hours (1–720) and limit (1–1000), and the default for hours. This exceeds what the bare schema conveys.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The first sentence names a specific verb and resource ("Search network flows") with a scope qualifier ("over a recent time window"), so an agent immediately knows what it returns. It doesn't, however, differentiate itself from the similar sibling top_risky_flows, leaving the agent to infer the difference between a general flow search and a ranked-risky-flows tool.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is implied rather than stated: the empty-string hint ("no filter (all flows in the window)") and the CSW filter example show how to invoke it, but there is no explicit when-to-use, when-not-to-use, or named alternative such as top_risky_flows. Adequate for a search tool but no routing guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
search_inventoryA
Search cluster inventory for workloads matching a field/value filter.
Args: value: The value to match (e.g. an IP, hostname fragment, OS string). field: The inventory dimension to filter on (default "ip"). Common fields: "ip", "hostname", "os", "user_annotations". match: CSW filter operator — "eq" (exact), "contains", "subnet", etc. Defaults to "eq". limit: Max results to return (1–1000).
Runs a read-only POST /openapi/v1/inventory/search. Returns a count and
the matching inventory records.
| Name | Required | Description | Default |
|---|---|---|---|
| field | No | ip | |
| limit | No | ||
| match | No | eq | |
| value | Yes |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden and largely delivers: it discloses that the underlying call is read-only despite being a POST, and states the return shape (count plus matching records). It does not cover auth requirements, rate limits, or pagination behavior beyond the limit parameter.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loads the core purpose before the Args list and keeps each parameter entry to a single line. The closing sentence restates the return shape that the existing output schema already covers, which is minor redundancy, but the structure is otherwise efficient.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a 4-parameter search tool with an output schema present, the definition supplies the read-only nature, the filtering model, and full parameter semantics. Only ancillary operational details (auth, rate limits) are absent, which are not essential to correct invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 0%, so the description must carry all parameter meaning, and it does: it explains value (with examples), field (default and common values), match (operators and default 'eq'), and limit (explicit 1–1000 range not present in the schema). Every parameter gains semantics beyond the bare schema titles.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('Search cluster inventory for workloads') plus the filtering mechanism (field/value). It implicitly distinguishes itself from search_flows by scoping to inventory/workloads, but never names a sibling explicitly, so differentiation is only inferable rather than stated.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Provides implied usage by listing common field values ('ip', 'hostname', 'os', 'user_annotations') and match operators, which hints at when the tool applies. However, there is no explicit when-to-use vs. when-not-to-use guidance and no mention of the closely related search_flows alternative.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
summarize_cluster_postureA
Summarize the cluster's security posture at a glance.
Returns headline KPIs for a security-leadership audience: total agents, how many are enforcing policy vs. visibility-only, the enforcement coverage percentage, and a breakdown of agents by type. This is the fastest way to gauge blast-radius exposure.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the behavioral burden. It implicitly signals a read-only aggregation and discloses the shape of the returned KPIs, but it says nothing about permissions, cost, latency, or whether any state is mutated — for a no-annotation tool that leaves real gaps.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded with the one-line purpose, followed by the KPI enumeration and a closing framing sentence. Every sentence is relevant, though the KPI list is somewhat verbose given an output schema already documents the return shape.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a parameterless, read-only summary with an output schema present, the description covers purpose, audience, and headline outputs adequately. The main omission is the absence of usage routing against the many sibling inventory/risk tools.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool takes zero parameters, so there is no parameter surface to document; the baseline for a 0-param tool is 4. Nothing in the description contradicts or complicates the empty schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb ('summarize') and resource ('cluster's security posture') and enumerates the exact KPIs returned (total agents, enforcing vs. visibility-only, coverage percentage, agent type breakdown). It is clearly distinguishable from the sibling list_*/get_* tools, though it never names an alternative explicitly.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The phrase 'fastest way to gauge blast-radius exposure' implies a high-level orientation use case, which is useful context. However, there is no explicit when-to-use vs. when-not guidance and no alternative sibling is named (e.g., when to prefer top_risky_flows or search_inventory for detail).
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
top_risky_flowsA
Rank risky-service exposure by counting recent flows to sensitive ports.
Scans the last hours for flows to high-risk management/data ports (RDP,
SMB, telnet, MSSQL, MySQL, PostgreSQL, Redis, MongoDB) and returns the ports
with the most observed flows. A fast way to spot lateral-movement surface.
Args: hours: Look-back window in hours (1–720, default 24). limit: Max flow samples to inspect per port (1–1000).
| Name | Required | Description | Default |
|---|---|---|---|
| hours | No | ||
| limit | No |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the behavior burden and does well: it discloses the look-back scoping, enumerates exactly which ports are considered high-risk, and describes the aggregation result (ports with the most observed flows). It does not state permissions or rate limits, but the read-only analytical nature is clear from 'Rank'/'Scans'.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded with the purpose sentence, then a scannable Args block. Slight overlap between the opening line and the second paragraph, but every sentence adds usable context with no padding.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need not be spelled out, and the description supplies the scan scope, port set, and parameter meaning. It stops short of noting whether the result is ranked or limited in size, but nothing critical is missing for correct invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, so the description must compensate, and it does: both parameters are explained with semantics (look-back window in hours; max flow samples inspected per port), valid ranges (1–720, 1–1000), and a default for hours. This fully covers the two-parameter gap.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (rank) and resource (risky-service exposure by counting flows to sensitive ports), and immediately names the domain (management/data ports) so an agent can distinguish it from siblings like search_flows or top_vulnerable_hosts. The port list makes the scope unambiguous.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It gives a use case ('A fast way to spot lateral-movement surface') but never states when to prefer this over alternatives such as search_flows or get_conversations, nor any prerequisites. Usage is implied rather than directed.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
top_vulnerable_hostsA
Rank the most vulnerable hosts in the cluster by CVE severity.
Iterates sensors, pulls each host's vulnerabilities, and scores them as
(critical * 10 + high). Returns the top limit hosts with their CVE counts.
Scanning is capped for safety on large clusters.
Args: limit: Number of top hosts to return (1–1000).
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden and does so well: it discloses the internal scoring formula (critical*10 + high), that it iterates sensors, and that scanning is capped for safety on large clusters. The main gap is that it never states this is a read-only/no-side-effect operation or what permissions are required.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loads the one-line purpose, then adds a compact explanation of mechanism and a short Args block. Every sentence carries weight, though the sensor-iteration detail is mildly implementation-flavored.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Output schema exists, so return-shape detail (top limit hosts with CVE counts) is a bonus rather than a requirement. For a single-parameter read tool with no annotations, the definition supplies enough mechanism and the safety cap to call it correctly; only auth/side-effect framing is absent.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema has 0% description coverage and only a default, but the description adds the valid range '(1–1000)' and the meaning of the value ('Number of top hosts to return'), which the schema does not provide. It fully compensates for the single undocumented parameter.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('Rank the most vulnerable hosts in the cluster by CVE severity') and gives the exact scoring formula, so an agent can distinguish it from get_workload_cves (per-workload) and summarize_cluster_posture. It does not name a sibling explicitly, keeping it short of a 5.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is implied by the purpose (use this to find the worst hosts), but there is no explicit when-to-use vs when-not, no mention of get_workload_cves or top_risky_flows as alternatives, and no stated prerequisites.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
15 tool updates
v0.1.0- First observed
get_conversations - First observed
get_workload - First observed
get_workload_cves - First observed
get_workload_packages - First observed
get_workspace_policies - First observed
list_forensic_profiles - First observed
list_policies_for_workload - First observed
list_scopes - First observed
list_sensors - First observed
list_workspaces - First observed
search_flows - First observed
search_inventory - First observed
summarize_cluster_posture - First observed
top_risky_flows - First observed
top_vulnerable_hosts
TDQS
Scored across 15 tools
Each tool targets a distinct resource or action, with clear separation between inventory, policy, flow, and vulnerability queries. Minor overlap exists between get_workload and search_inventory for single-host lookup, and between list_scopes and list_workspaces as hierarchical grouping concepts, but descriptions clarify their boundaries.
All tool names use snake_case and generally follow a verb_noun pattern (list_, get_, search_, summarize_). The ranking tools top_risky_flows and top_vulnerable_hosts deviate slightly with a top_ prefix, but remain readable and consistent with each other.
Fifteen tools is within the well-scoped range and each covers a distinct facet of the CSW domain: inventory, sensors, scopes, policies, flows, vulnerabilities, and forensic profiles. No tool appears redundant or unnecessary for the breadth of surface presented.
The surface is entirely read-only, offering broad coverage for analysis and posture assessment but no create/update/delete operations for policies, workspaces, scopes, sensors, or forensic profiles. This is a notable lifecycle gap that will prevent agents from performing management actions through this MCP.
Maintenance
Related MCP Connectors
Query your org's data in natural language — read-only MCP access to SQL, NoSQL, files & warehouses.
The Cortex MCP server provides read-only access to real-time engineering context from the Cortex developer portal, allowing AI coding assistants to answer natural language questions about your organization's catalog (microservices, libraries, domains, teams, infrastructure), scorecards (engineering standards and best practices), initiatives (goals and deadlines), and Engineering Intelligence metrics. It includes tools for querying documentation, tracking personal entities, and accessing AI-assisted insights across the entire Cortex ecosystem.
Query your warehouse or a CSV with Claude/ChatGPT over MCP, governed by table-level ACL + audit.
An MCP server that provides an API to LLMs to manage their JumpCloud resources.
Related MCP Servers
- AlicenseNot gradedqualityFmaintenanceA read-only MCP server that exposes Quickwit log search and aggregations to LLM clients, enabling natural language log investigation.Apache 2.0
- AlicenseAqualityCmaintenanceSecurity-first, read-only MCP server for Microsoft SQL Server, enabling safe natural-language querying of databases.513 npmMIT
- AlicenseAqualityCmaintenanceA read-only MCP server that enables AI assistants to query ServiceNow instances—incidents, changes, users, CMDB—with malformed query linting and injection protection.7MIT
- AlicenseNot gradedqualityBmaintenanceA read-only MCP server for Cisco Meraki Dashboard, enabling LLMs to discover devices, check health, troubleshoot, and generate reports via natural language.MIT