Skip to main content
Glama

csw-mcp

Query Cisco Secure Workload in natural language — a read-only MCP server for Cursor, Claude Desktop, Grok, Codex, and Gemini.

Visitors

License: Apache 2.0 Python 3.10+ MCP Read-only uv

Ask “how many agents are enforcing policy?” or “which hosts have exploitable critical CVEs?” — and get an answer, not an API call.


What it is

csw-mcp is a Model Context Protocol server that lets MCP clients (Cursor, Claude Desktop, Grok, Codex, and Gemini) query a Cisco Secure Workload (CSW / Tetration) cluster in plain English. It is for anyone who wants to use CSW and get posture answers without writing HMAC-signed API calls.

flowchart TB
    ui["1 · In the Secure Workload UI<br/>User Menu → API Keys → Create API Key"]
    env["2 · On your laptop, copy .env.example to .env<br/>CSW_API_URL · CSW_API_KEY · CSW_API_SECRET"]
    ask["3 · Ask in Cursor, Claude Desktop,<br/>Grok, Codex, or Gemini"]
    local["4 · csw-mcp reads that .env<br/>and signs each call with the API secret"]
    tenant["5 · Your Secure Workload tenant"]
    reply["6 · The answer comes back in the chat"]

    ui --> env --> ask --> local
    local -->|"read-only, no OAuth"| tenant
    tenant -->|"scopes · agents · workspaces<br/>inventory · forensic profiles"| reply

    classDef step fill:#F8FAFC,stroke:#005073,color:#020617;
    classDef cred fill:#FFFBEB,stroke:#d97706,color:#020617;
    classDef cisco fill:#00bceb,stroke:#005073,color:#ffffff;
    class ask,local,reply step;
    class ui,env cred;
    class tenant cisco;

Where the cluster info goes: a file named .env in this repo (it stays on your machine and is never committed). No OAuth, no browser login, and no extra token service. Secure Workload uses an API key plus its matching secret. Create that pair in the product UI under User Menu → API Keys → Create API Key, then put these three lines in .env:

CSW_API_URL=https://your-cluster.tetrationcloud.com
CSW_API_KEY=your_api_key_here
CSW_API_SECRET=your_api_secret_here

CSW_API_URL is the cluster address only, with no path on the end. The key needs read access for sensors, flows, and policy. Setup steps are in docs/INSTALL.md.

Start with one of these. They are the current capabilities confirmed on a live tenant:

  • “Show me the scope tree.”

  • “List the agents on this cluster.”

  • “What workspaces are defined?”

  • “Find the workload for this IP.”

  • “Which forensic profiles are on this cluster?”

The server only reads. It does not create, change, or delete anything on the tenant, and it listens only on a local stdio pipe. The HMAC signing and module layout are in docs/ARCHITECTURE.md.

This repo is companion tooling, not official Cisco documentation. Confirm behavior against your cluster's in-product help and the Cisco Secure Workload product documentation.


Related MCP server: MSSQL-MCP

New to Cisco Secure Workload?

Cisco Secure Workload (also called Tetration) watches how servers talk to each other, then lets you write firewall-style rules that follow the workload instead of a fixed IP. The goal is simple: if one machine is compromised, the attacker should not be able to walk sideways to the next one. That is micro-segmentation, and the size of the damage an attacker can do is the blast radius.

You do not need to know the product to use this server. Ask a question in English. The model calls the tools below and answers in plain language.

Term you will see

Plain meaning

Agent / sensor

Software on a host that reports connections. In enforcement mode it also blocks traffic the policy does not allow. In visibility mode it only watches.

Scope

A folder in the inventory tree (for example Production, Databases, WebTier) used to group workloads and attach policy.

Workspace / application

A policy container. ADM (Application Dependency Mapping) looks at real traffic and proposes a starter ruleset.

Flow

One observed connection: who talked to whom, on which port, and whether policy allowed it.

Conversation

A summarized "these two groups talk on this port" pair that ADM uses to draft policy.

Workload

One host, VM, or pod that CSW is tracking.

If you want the longer story — why this exists, how a POV is run, and a video learning path — start with CSW User Education.


Quickstart

# 1. Enter the repo
cd csw-mcp

# 2. Create the environment and install (uv — https://astral.sh/uv)
uv venv
uv pip install -e .

# 3. Configure credentials
cp .env.example .env            # then edit with your cluster URL / key / secret

# 4. Register with Cursor (idempotent)
bash scripts/install-cursor.sh

# 5. Restart Cursor, then ask: "Summarize my CSW cluster posture."

Verify it loaded:

uv run python -c "from csw_mcp.server import mcp; print('tools:', len(mcp._tool_manager._tools), 'prompts:', len(mcp._prompt_manager._prompts))"
# tools: 15 prompts: 3

# Optional: smoke-test every tool against your own cluster
uv run python tests/test_tools_live.py

Full step-by-step with screenshots-as-ascii: docs/INSTALL.md.


Capabilities

Tools (15)

Name

What it does

list_scopes

List the scope hierarchy (GET /openapi/v1/app_scopes)

list_sensors

List agents/sensors (uuid, hostname, agent_type, platform, IPs)

search_inventory

Search inventory by field/value filter

get_workload

Fetch one workload's inventory record by IP

summarize_cluster_posture

Headline posture KPIs (enforcement coverage, agents by type)

list_workspaces

List application workspaces (policy folders / ADM scopes)

get_workspace_policies

List policies defined in a workspace

list_policies_for_workload

List policies currently applied to a workload

search_flows

Search network flows over a recent time window

get_conversations

List ADM conversations (talker pairs) for a workspace

top_risky_flows

Rank risky-service exposure (RDP/SMB/telnet/DB ports)

get_workload_cves

List CVEs on a workload + severity tally

get_workload_packages

List installed packages on a workload

top_vulnerable_hosts

Rank hosts by CVE severity (critical×10 + high)

list_forensic_profiles

List configured forensic profiles

Resources (4)

URI

What it does

csw://cluster/info

Cluster URL, config state, quick scope/agent counts

csw://scopes

Scope hierarchy (cached ~60s)

csw://snapshots/latest

Newest local snapshot-*.json (via $CSW_POV_TEMPLATE)

csw://reports/executive-latest

Newest local executive-summary markdown

Prompts (3)

csw/triage-blast-radius · csw/weekly-posture-review · csw/pov-closeout

See docs/USAGE.md for example prompts and when to use each tool.


Current capabilities

Live test SaaS tenant

Confirmed on a live SaaS tenant. Each row below returned data. Full notes: docs/TESTED.md.

Feature

What you get

Try this

✅

list_scopes

The scope tree

“Show me the scope tree.”

✅

list_sensors

Agents, hostnames, platforms, addresses

“List the agents on this cluster.”

✅

list_workspaces

Application workspaces

“What workspaces are defined?”

✅

search_inventory

Inventory matches for an IP or field

“Find the workload for this IP.”

✅

get_workload

One workload record

“Show me the workload at this IP.”

✅

list_forensic_profiles

Configured forensic profiles

“Which forensic profiles are on this cluster?”

✅

summarize_cluster_posture

Agent count, scope count, and enforcement coverage

“How many agents are enforcing?”

✅

get_workspace_policies

Absolute and default policies for a workspace

“Show the policies in this workspace.”

✅

search_flows

Recent flows in a scope

“Show recent flows in the root scope.”

✅

get_conversations

ADM conversations for a workspace

“Show the conversations for this workspace.”

✅

top_risky_flows

Risky ports with recent flow activity

“Which risky ports have recent traffic?”


Examples

Five fully-synthetic walkthroughs live in examples/, each with a question, the tool-call flow, and a rendered HTML deliverable:


Configuration

Credentials come from a project-level .env (never committed — see .gitignore):

Variable

Required

Notes

CSW_API_URL

yes

Cluster base URL, no trailing slash

CSW_API_KEY

yes

API key (hex) from CSW UI → API Keys

CSW_API_SECRET

yes

HMAC signing secret paired with the key

CSW_VERIFY_SSL

no

Set false only behind a TLS-inspecting proxy

CSW_MCP_ENV

no

Explicit path to an alternate env file

CSW_POV_TEMPLATE

no

Path to a CSW_POV_Template checkout (enables snapshot/report resources)

Generate an API key in the CSW UI (User Menu → API Keys → Create API Key) with read capabilities: sensor_management, flow_inventory_query, app_policy_management.


Safety & design principles

  • Read-only. Only GET and read-only search POSTs; no create/update/delete tools.

  • stdio transport. No listening socket → no DNS-rebinding / CSRF surface.

  • Single-purpose tools. No "run arbitrary request" escape hatch.

  • Bounded. Result limits are clamped; aggregators cap fan-out and pagination.

  • No secrets in code. Credentials load from a git-ignored .env; nothing is logged.

  • Minimal output. Tool results are projected to the fields you need.

More detail: docs/ARCHITECTURE.md.


Documentation

Doc

Contents

docs/INSTALL.md

Full install, wiring, verification

docs/USAGE.md

Example prompts, tool selection, combining tools

docs/TROUBLESHOOTING.md

Top 10 "it broke" fixes

docs/CONTRIBUTING.md

How to add a new tool (+ test)

docs/ARCHITECTURE.md

Components, modules, HMAC auth flow


Development

The CSW API client (src/csw_mcp/vendor/csw_api.py, csw_helpers.py) is vendored from the generic CSW_POV_Template project and should not be edited by hand. Re-sync it with:

CSW_POV_TEMPLATE=/path/to/CSW_POV_Template bash scripts/sync-vendor.sh

Regenerate the example reports:

python3 examples/build_examples.py

Same author, public repos. Use these when you want the background, a POV plan, or the script toolkit this server sits on top of. Customer-specific repos are intentionally not listed here.

Learn the product

Repo

Use it when you want…

CSW User Education

A plain-language intro, video library, and onboarding path

CSW POV Playbook

A field guide any SE can run: scope, observe, model policy, enforce safely, executive readout

CSW Personas

Who shows up in a deal, what they care about, and which CSW topics to lead with

Cisco product docs

Official Secure Workload documentation

Query and report on a cluster

Repo

How it relates to csw-mcp

CSW Operations Toolkit

The Python scripts (snapshots, flows, policies, HTML reports) whose API client this server vendors. Use the scripts for batch reports; use csw-mcp to ask questions in chat.

csw-logs-check

Reads an agent diagnostic log bundle (enforcement timing, policy versions) — a different input than the live API this server calls.

CSW Compliance Mapping

How CSW controls map to HIPAA, SOC 2, PCI DSS, NIST 800-53, ISO 27001, and related frameworks

Blast radius demo

A visual companion to the blast-radius-triage example in this repo

Install agents and connect other systems

Repo

Topic

Kubernetes / OpenShift agent guide

Install the agent on cluster nodes and enforce pod/service policy

Kubernetes integration

Connector labels, DaemonSet, container CVE scanning

OpenShift integration

Same pattern, plus the privileged SCC OpenShift requires

CSW Virtual on vSphere

Deploy the on-prem virtual cluster (OVA, site config, hardening)

Secure Firewall integration

Host policy plus firewall (NSEL) visibility

ServiceNow connector

Inventory enrichment labels from ServiceNow

ACI integration

Align CSW scopes with ACI EPGs


License

Apache-2.0.

Available Tools

15 tools
get_conversationsA

List ADM conversations (observed talker pairs) for a workspace.

Args: app_id: The workspace/application id (from list_workspaces). version: Optional ADM version; omit for the latest.

Reads GET /openapi/v1/conversations/{app_id}, paginating up to a safety cap. Conversations are the raw src→dst:port pairs ADM used to propose policy.

ParametersJSON Schema
NameRequiredDescriptionDefault
app_idYes
versionNo

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the burden and does useful work: it discloses the underlying HTTP verb (GET /openapi/v1/conversations/{app_id}), identifies the call as a read, and warns that it paginates 'up to a safety cap'. It stops short of stating auth needs or what happens at the cap.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads the purpose in one line, then parameter meanings, then behavioral notes about the endpoint and pagination. Well-organized with no filler, though the Args block slightly restates what the parameter list already implies.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return values need not be described. Given the low-complexity two-parameter read, the description covers purpose, parameters, read-only nature, and pagination behavior adequately; only auth/truncation semantics are left implicit.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must compensate and largely does: app_id is explained as the workspace/application id sourced from list_workspaces, and version is explained as optional with 'omit for the latest'. It could say more about the version value's meaning, but both parameters are given usable semantics.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (List) and resource (ADM conversations / observed talker pairs) scoped to a workspace. The parenthetical 'raw src→dst:port pairs ADM used to propose policy' distinguishes it from sibling flow-search tools like search_flows and top_risky_flows without needing their schemas.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is implied by the resource ('conversations for a workspace') and it helpfully points to list_workspaces as the source of app_id. However, it never states when to choose this over search_flows or other inventory/flow tools, and gives no exclusions.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

get_workloadA

Fetch the inventory record for a single workload by IP address.

Looks up the workload via a read-only inventory search for the exact IP. Returns the full record if found, or a graceful not-found message. Use this to inspect one host's annotations, scopes, and attributes.

ParametersJSON Schema
NameRequiredDescriptionDefault
addressYes

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations supplied, the description carries the full behavioral burden and does disclose two meaningful traits: the lookup is read-only (no mutation risk) and a missing host returns a graceful not-found message rather than an error. It omits permission/auth requirements and rate limits, which keeps it short of a 5.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three short sentences, front-loaded with the core action and ending with the intended use. Slight redundancy between 'Fetch the inventory record' and 'Looks up the workload via a read-only inventory search' costs it a perfect score.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a single-parameter read tool with an output schema available to describe return shape, the description covers action, scope, safety, and failure behavior. Nothing an agent needs in order to invoke it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 0% and the lone 'address' parameter has no schema description, but the description compensates by specifying that the value is an IP address and that the match must be exact. That is the key semantics an agent needs for a single required string argument.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (fetch/look up), resource (inventory record for a single workload) and scope (by exact IP address). It implicitly separates itself from the sibling 'search_inventory' by emphasizing 'a single workload' and 'the exact IP', though it never names an alternative tool outright.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

'Use this to inspect one host's annotations, scopes, and attributes' gives clear context for when the tool applies. There are no explicit exclusions or named alternatives, so an agent must infer that bulk queries belong to search_inventory.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

get_workload_cvesA

List CVEs / vulnerabilities detected on a single workload.

Args: uuid: The workload/sensor UUID (from list_sensors).

Returns records from GET /openapi/v1/workload/{uuid}/vulnerabilities plus a severity tally (critical/high/medium/low).

ParametersJSON Schema
NameRequiredDescriptionDefault
uuidYes

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A3.6/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden. It does disclose that this is a read operation via the underlying 'GET /openapi/v1/workload/{uuid}/vulnerabilities' endpoint and that results include a severity tally (critical/high/medium/low), which adds real behavioral context. It says nothing about pagination, result limits, or permissions, so gaps remain.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core purpose in one sentence, followed by tightly scoped Args and Returns notes. Every line earns its place; the only minor overhead is the docstring-style formatting.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given a single required parameter and an existing output schema, the definition supplies what an agent needs: purpose, parameter provenance, and return-shape hint. Minor omissions around pagination and access requirements keep it short of complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must compensate for the single parameter, and it does: it identifies `uuid` as the workload/sensor UUID and points to `list_sensors` as the source. This adds provenance beyond the bare 'string' type, though it doesn't specify format or validation.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('List CVEs / vulnerabilities') with explicit scope ('on a single workload'). An agent can distinguish it from inventory-oriented siblings like get_workload_packages or the aggregate top_vulnerable_hosts, though no sibling is named directly.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The Args note gives useful provenance for the required parameter ('from `list_sensors`'), which tells the agent where to obtain input. However, there is no explicit when-to-use guidance relative to alternatives such as top_vulnerable_hosts, and no stated prerequisites or exclusions.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

get_workload_packagesA

List installed software packages on a single workload.

Args: uuid: The workload/sensor UUID (from list_sensors).

Returns records from GET /openapi/v1/workload/{uuid}/packages.

ParametersJSON Schema
NameRequiredDescriptionDefault
uuidYes

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A3.6/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full disclosure burden. "List" implies a read-only operation and it discloses the underlying endpoint, but it says nothing about pagination, result limits, or permissions required to enumerate packages on a host. Adequate but incomplete for a no-annotation tool.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the purpose, then a short Args block and a return-source line. Every sentence carries information; the endpoint disclosure is mildly redundant with the description's first sentence but not wasteful.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return-format explanation is unnecessary, and the single required parameter is documented both in prose and sourcing. For a simple read-only list call, what remains missing (pagination/limits) is minor.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 0% — the schema only declares a bare string named "uuid" — so the description must compensate, and it does: it explains that the parameter is the workload/sensor UUID and that it comes from `list_sensors`. The only gap is that it does not clarify the accepted UUID format.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ("List installed software packages on a single workload"), which is clearly distinct from siblings like get_workload_cves or get_workload. It does not explicitly contrast itself with search_inventory, the closest alternative, but the scope word "single workload" already narrows intent.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage via the singular-workload scope and tells the agent where the uuid comes from (`list_sensors`), which is genuinely useful routing information. However, it never states when to use this instead of search_inventory or other inventory tools, nor any prerequisites.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

get_workspace_policiesA

List the policies defined in a workspace.

Args: app_id: The workspace/application id (from list_workspaces).

Returns the policy records from GET /openapi/v1/applications/{app_id}/policies.

ParametersJSON Schema
NameRequiredDescriptionDefault
app_idYes

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A3.6/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden. It discloses the underlying endpoint (GET /openapi/v1/applications/{app_id}/policies), which signals a safe read, but says nothing about auth requirements, pagination, result caps, or whether the list is complete or filtered.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded purpose sentence, then a compact Args note and a return line. Mildly redundant to restate the return records when an output schema already exists, but nothing is padded.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a one-parameter read tool with an output schema, the description covers purpose, the single argument, and its source. The remaining gap is routing guidance against the near-identical sibling list_policies_for_workload, which the description never addresses.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must compensate, and it does: app_id is explained as the 'workspace/application id' plus where to obtain it (list_workspaces). That is meaningfully more than the bare 'App Id' title in the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('List the policies defined in a workspace'), and the workspace scope implicitly separates it from the sibling list_policies_for_workload. It stops short of naming that sibling explicitly, so an agent must infer the boundary from scope alone.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is only implied — clearly a read for a given workspace — and the description never states when to prefer it over list_policies_for_workload or list_policies_for_workload. The one useful nudge is the provenance hint that app_id comes 'from `list_workspaces`', which chains the tool correctly.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

list_forensic_profilesB

List configured forensic profiles (behavioral rule sets for agents).

Returns records from GET /openapi/v1/inventory_config/forensic_profiles.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

B3.4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden. Naming the underlying GET endpoint implies a read-only, non-mutating call, which is useful signal, but it says nothing about pagination, permissions, filtering, or result volume.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two short sentences, front-loaded with the purpose. The second sentence is partly redundant metadata but does convey read-only semantics via the HTTP verb.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return values need not be described, and there are no parameters to document. The only meaningful gap is the absence of explicit read-only/pagination context for an unannotated tool, which is minor.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool takes zero parameters and the schema has no properties, so there is nothing for the description to disambiguate; baseline 4 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource ('List configured forensic profiles') and adds a clarifying gloss that they are 'behavioral rule sets for agents'. It does not explicitly differentiate itself from siblings like list_scopes or list_sensors, but the resource noun is distinct enough to identify it.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no guidance on when to call this versus alternatives, nor any prerequisite or context conditions. The reader must infer usage entirely from the resource name.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

list_policies_for_workloadA

List the policies that currently apply to a single workload.

Args: uuid: The workload/sensor UUID (from list_sensors).

Returns the policies from GET /openapi/v1/workload/{uuid}/policies — useful to understand exactly what a given host is allowed to talk to.

ParametersJSON Schema
NameRequiredDescriptionDefault
uuidYes

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A3.6/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden. It discloses that this is a read against GET /openapi/v1/workload/{uuid}/policies and identifies the data source, but says nothing about pagination, permissions, or result shape. Adequate but not rich for an unannotated tool.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded purpose sentence followed by a scoped args block and a short rationale. Slightly verbose around the endpoint sentence, but each line carries information without waste.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return values need not be spelled out, and the description still names the underlying endpoint and the practical intent. For a single-parameter read tool this is close to sufficient, with only permissions/pagination details absent.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 0% and there is one parameter, so the description must compensate. It does: 'uuid: The workload/sensor UUID (from list_sensors)' tells the agent what the value is and where to obtain it, which is more than the schema offers.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource with clear scope ('policies that currently apply to a single workload'), which distinguishes it from the workspace-level sibling get_workspace_policies. It stops short of explicitly naming that sibling, but the workload-vs-workspace scope is unambiguous.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is implied by 'useful to understand exactly what a given host is allowed to talk to' and by pointing to list_sensors as the source of the uuid. There is no explicit when-not guidance or named alternative tool.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

list_scopesA

List the CSW scopes (the hierarchy that organizes workloads and policy).

Returns a count and the raw scope records from GET /openapi/v1/app_scopes. Use this to understand how the cluster is segmented before drilling in.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A3.7/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden. It discloses useful behavioral detail: the tool is a read ('List'), returns a count plus raw records, and maps to GET /openapi/v1/app_scopes. It does not state whether the list is paginated, complete, or what permissions/authentication are required, leaving gaps for a no-annotation tool.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three short sentences, front-loaded with the resource and its meaning, followed by return shape and usage context. Every sentence adds value with no redundancy.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so the description need not detail return values, though it helpfully summarizes them. For a zero-parameter read tool this covers purpose, usage, and output. Pagination and completeness of the listing are the only minor omissions.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool takes zero parameters and schema coverage is 100%, so there are no parameter semantics to explain and the baseline is 4.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description gives a specific verb+resource ('List the CSW scopes') and defines the resource's role ('the hierarchy that organizes workloads and policy'), so an agent can tell it is enumerating cluster segmentation structures. It does not explicitly contrast with siblings like list_workspaces or list_sensors, so it stops short of full sibling differentiation.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

'Use this to understand how the cluster is segmented before drilling in' supplies a clear usage context and sequencing hint. However, no alternative tool is named and no exclusions or prerequisites are stated, so the guidance remains implied rather than explicit.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

list_sensorsA

List the agents/sensors registered on the cluster (summarized).

Each entry includes uuid, hostname, agent_type (ENFORCER / VISIBILITY / …), platform, and the host's IPs. limit caps how many records are returned (1–1000). Use this to inventory the fleet and spot which hosts run an enforcing agent vs. visibility-only.

ParametersJSON Schema
NameRequiredDescriptionDefault
limitNo

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A3.8/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations, so the description carries the full behavioral burden. It discloses that results are summarized and enumerates returned fields, but says nothing about permissions, pagination, or what happens when the fleet exceeds the limit ceiling — gaps that matter for a list tool with zero annotation coverage.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the purpose, then the returned-field summary and the limit semantics. Every sentence carries information; the only mild redundancy is listing return fields when an output schema already exists.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With an output schema present, the description need not explain return values yet still does so helpfully. For a single-parameter read tool with no annotations, the coverage of purpose, fields, and limit range makes it adequately complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 0%, so the description must compensate, and it does: 'limit caps how many records are returned (1–1000).' That supplies both meaning and the valid range the schema lacks, though the default of 100 is left unmentioned.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('List the agents/sensors registered on the cluster') plus scope ('summarized'), so the operation is unambiguous. It does not name or contrast itself with siblings like search_inventory or summarize_cluster_posture, which is the only thing keeping it from a 5.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly says what the tool is for: 'Use this to inventory the fleet and spot which hosts run an enforcing agent vs. visibility-only.' That is a clear usage context, but it offers no exclusions or pointer to alternatives for filtered/targeted queries.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

list_workspacesA

List application workspaces (policy folders / ADM scopes).

Returns the workspaces from GET /openapi/v1/applications. Each workspace groups policy rules and ADM versions. Use the returned id with get_workspace_policies or get_conversations.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the burden. It discloses the underlying endpoint (GET /openapi/v1/applications), states what is returned (the workspaces), and explains the grouping semantics of the resource. For a zero-parameter read-only list this is solid; it lacks only pagination/size hints, a minor gap.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three tight sentences, front-loaded with the noun phrase and its disambiguation, then the endpoint, then the follow-up tool routing. Nothing is padding; every sentence adds usable information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return-value detail is not the description's job, and the description still volunteers the useful `id`-based follow-up. The only omission is a contrast with the sibling list_scopes, which would fully close the loop on selection.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool takes zero parameters, which sets the baseline at 4. The description correctly adds no parameter detail because none exists, and the empty schema is fully consistent with a parameterless lister.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Specific verb+resource ('List application workspaces') with a clarifying gloss ('policy folders / ADM scopes') and a note on what each workspace groups. An agent can distinguish this from siblings like list_scopes or list_policies_for_workload without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly routes the agent onward: use the returned `id` with `get_workspace_policies` or `get_conversations`. That cleanly describes downstream usage. It does not, however, say when to prefer this over the similar-sounding `list_scopes` sibling, so it falls short of a full when/when-not treatment.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

search_flowsA

Search network flows over a recent time window.

Args: filter_json: A CSW flow filter as a JSON string, e.g. '{"type":"eq","field":"dst_port","value":3389}'. Pass an empty string for no filter (all flows in the window). hours: Look-back window in hours (1–720, default 24). limit: Max flow records to return (1–1000).

Runs a read-only POST /openapi/v1/flowsearch with t0 = now-hours, t1 = now.

ParametersJSON Schema
NameRequiredDescriptionDefault
hoursNo
limitNo
filter_jsonNo

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations present, the description carries the full burden and does disclose the key behavioral trait: it "Runs a read-only POST /openapi/v1/flowsearch with t0 = now-hours, t1 = now." This tells the agent the operation is non-mutating and how the time window is computed. It omits auth requirements and any rate/result-size caveats.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded purpose sentence, then a clean Args block, then one line of implementation detail. Every element earns its place, though the trailing endpoint description is somewhat module-specific rather than agent-facing.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Because an output schema exists, return values need not be described, and all three parameters are documented with ranges and an example. The remaining gap is the absence of auth/permission context or pagination behavior for a tool that can return up to 1000 records.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, yet the description compensates fully: it gives a concrete filter JSON example with field syntax, the empty-string default meaning, valid ranges for hours (1–720) and limit (1–1000), and the default for hours. This exceeds what the bare schema conveys.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The first sentence names a specific verb and resource ("Search network flows") with a scope qualifier ("over a recent time window"), so an agent immediately knows what it returns. It doesn't, however, differentiate itself from the similar sibling top_risky_flows, leaving the agent to infer the difference between a general flow search and a ranked-risky-flows tool.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is implied rather than stated: the empty-string hint ("no filter (all flows in the window)") and the CSW filter example show how to invoke it, but there is no explicit when-to-use, when-not-to-use, or named alternative such as top_risky_flows. Adequate for a search tool but no routing guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

search_inventoryA

Search cluster inventory for workloads matching a field/value filter.

Args: value: The value to match (e.g. an IP, hostname fragment, OS string). field: The inventory dimension to filter on (default "ip"). Common fields: "ip", "hostname", "os", "user_annotations". match: CSW filter operator — "eq" (exact), "contains", "subnet", etc. Defaults to "eq". limit: Max results to return (1–1000).

Runs a read-only POST /openapi/v1/inventory/search. Returns a count and the matching inventory records.

ParametersJSON Schema
NameRequiredDescriptionDefault
fieldNoip
limitNo
matchNoeq
valueYes

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden and largely delivers: it discloses that the underlying call is read-only despite being a POST, and states the return shape (count plus matching records). It does not cover auth requirements, rate limits, or pagination behavior beyond the limit parameter.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads the core purpose before the Args list and keeps each parameter entry to a single line. The closing sentence restates the return shape that the existing output schema already covers, which is minor redundancy, but the structure is otherwise efficient.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 4-parameter search tool with an output schema present, the definition supplies the read-only nature, the filtering model, and full parameter semantics. Only ancillary operational details (auth, rate limits) are absent, which are not essential to correct invocation.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 0%, so the description must carry all parameter meaning, and it does: it explains value (with examples), field (default and common values), match (operators and default 'eq'), and limit (explicit 1–1000 range not present in the schema). Every parameter gains semantics beyond the bare schema titles.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Search cluster inventory for workloads') plus the filtering mechanism (field/value). It implicitly distinguishes itself from search_flows by scoping to inventory/workloads, but never names a sibling explicitly, so differentiation is only inferable rather than stated.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Provides implied usage by listing common field values ('ip', 'hostname', 'os', 'user_annotations') and match operators, which hints at when the tool applies. However, there is no explicit when-to-use vs. when-not-to-use guidance and no mention of the closely related search_flows alternative.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

summarize_cluster_postureA

Summarize the cluster's security posture at a glance.

Returns headline KPIs for a security-leadership audience: total agents, how many are enforcing policy vs. visibility-only, the enforcement coverage percentage, and a breakdown of agents by type. This is the fastest way to gauge blast-radius exposure.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A3.6/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the behavioral burden. It implicitly signals a read-only aggregation and discloses the shape of the returned KPIs, but it says nothing about permissions, cost, latency, or whether any state is mutated — for a no-annotation tool that leaves real gaps.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the one-line purpose, followed by the KPI enumeration and a closing framing sentence. Every sentence is relevant, though the KPI list is somewhat verbose given an output schema already documents the return shape.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a parameterless, read-only summary with an output schema present, the description covers purpose, audience, and headline outputs adequately. The main omission is the absence of usage routing against the many sibling inventory/risk tools.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool takes zero parameters, so there is no parameter surface to document; the baseline for a 0-param tool is 4. Nothing in the description contradicts or complicates the empty schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb ('summarize') and resource ('cluster's security posture') and enumerates the exact KPIs returned (total agents, enforcing vs. visibility-only, coverage percentage, agent type breakdown). It is clearly distinguishable from the sibling list_*/get_* tools, though it never names an alternative explicitly.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The phrase 'fastest way to gauge blast-radius exposure' implies a high-level orientation use case, which is useful context. However, there is no explicit when-to-use vs. when-not guidance and no alternative sibling is named (e.g., when to prefer top_risky_flows or search_inventory for detail).

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

top_risky_flowsA

Rank risky-service exposure by counting recent flows to sensitive ports.

Scans the last hours for flows to high-risk management/data ports (RDP, SMB, telnet, MSSQL, MySQL, PostgreSQL, Redis, MongoDB) and returns the ports with the most observed flows. A fast way to spot lateral-movement surface.

Args: hours: Look-back window in hours (1–720, default 24). limit: Max flow samples to inspect per port (1–1000).

ParametersJSON Schema
NameRequiredDescriptionDefault
hoursNo
limitNo

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the behavior burden and does well: it discloses the look-back scoping, enumerates exactly which ports are considered high-risk, and describes the aggregation result (ports with the most observed flows). It does not state permissions or rate limits, but the read-only analytical nature is clear from 'Rank'/'Scans'.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the purpose sentence, then a scannable Args block. Slight overlap between the opening line and the second paragraph, but every sentence adds usable context with no padding.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return values need not be spelled out, and the description supplies the scan scope, port set, and parameter meaning. It stops short of noting whether the result is ranked or limited in size, but nothing critical is missing for correct invocation.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must compensate, and it does: both parameters are explained with semantics (look-back window in hours; max flow samples inspected per port), valid ranges (1–720, 1–1000), and a default for hours. This fully covers the two-parameter gap.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (rank) and resource (risky-service exposure by counting flows to sensitive ports), and immediately names the domain (management/data ports) so an agent can distinguish it from siblings like search_flows or top_vulnerable_hosts. The port list makes the scope unambiguous.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives a use case ('A fast way to spot lateral-movement surface') but never states when to prefer this over alternatives such as search_flows or get_conversations, nor any prerequisites. Usage is implied rather than directed.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

top_vulnerable_hostsA

Rank the most vulnerable hosts in the cluster by CVE severity.

Iterates sensors, pulls each host's vulnerabilities, and scores them as (critical * 10 + high). Returns the top limit hosts with their CVE counts. Scanning is capped for safety on large clusters.

Args: limit: Number of top hosts to return (1–1000).

ParametersJSON Schema
NameRequiredDescriptionDefault
limitNo

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A3.8/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden and does so well: it discloses the internal scoring formula (critical*10 + high), that it iterates sensors, and that scanning is capped for safety on large clusters. The main gap is that it never states this is a read-only/no-side-effect operation or what permissions are required.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads the one-line purpose, then adds a compact explanation of mechanism and a short Args block. Every sentence carries weight, though the sensor-iteration detail is mildly implementation-flavored.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Output schema exists, so return-shape detail (top limit hosts with CVE counts) is a bonus rather than a requirement. For a single-parameter read tool with no annotations, the definition supplies enough mechanism and the safety cap to call it correctly; only auth/side-effect framing is absent.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema has 0% description coverage and only a default, but the description adds the valid range '(1–1000)' and the meaning of the value ('Number of top hosts to return'), which the schema does not provide. It fully compensates for the single undocumented parameter.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Rank the most vulnerable hosts in the cluster by CVE severity') and gives the exact scoring formula, so an agent can distinguish it from get_workload_cves (per-workload) and summarize_cluster_posture. It does not name a sibling explicitly, keeping it short of a 5.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is implied by the purpose (use this to find the worst hosts), but there is no explicit when-to-use vs when-not, no mention of get_workload_cves or top_risky_flows as alternatives, and no stated prerequisites.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 15 tool updatesv0.1.0
    • First observedget_conversations
    • First observedget_workload
    • First observedget_workload_cves
    • First observedget_workload_packages
    • First observedget_workspace_policies
    • First observedlist_forensic_profiles
    • First observedlist_policies_for_workload
    • First observedlist_scopes
    • First observedlist_sensors
    • First observedlist_workspaces
    • First observedsearch_flows
    • First observedsearch_inventory
    • First observedsummarize_cluster_posture
    • First observedtop_risky_flows
    • First observedtop_vulnerable_hosts

TDQS

A3.7/5.0

Scored across 15 tools

Disambiguation4/5

Each tool targets a distinct resource or action, with clear separation between inventory, policy, flow, and vulnerability queries. Minor overlap exists between get_workload and search_inventory for single-host lookup, and between list_scopes and list_workspaces as hierarchical grouping concepts, but descriptions clarify their boundaries.

Naming Consistency4/5

All tool names use snake_case and generally follow a verb_noun pattern (list_, get_, search_, summarize_). The ranking tools top_risky_flows and top_vulnerable_hosts deviate slightly with a top_ prefix, but remain readable and consistent with each other.

Tool Count5/5

Fifteen tools is within the well-scoped range and each covers a distinct facet of the CSW domain: inventory, sensors, scopes, policies, flows, vulnerabilities, and forensic profiles. No tool appears redundant or unnecessary for the breadth of surface presented.

Completeness3/5

The surface is entirely read-only, offering broad coverage for analysis and posture assessment but no create/update/delete operations for policies, workspaces, scopes, sensors, or forensic profiles. This is a notable lifecycle gap that will prevent agents from performing management actions through this MCP.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    F
    maintenance
    A read-only MCP server that exposes Quickwit log search and aggregations to LLM clients, enabling natural language log investigation.
    Apache 2.0
  • A
    license
    A
    quality
    C
    maintenance
    Security-first, read-only MCP server for Microsoft SQL Server, enabling safe natural-language querying of databases.
    5
    13 npm
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    A read-only MCP server that enables AI assistants to query ServiceNow instances—incidents, changes, users, CMDB—with malformed query linting and injection protection.
    7
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    A read-only MCP server for Cisco Meraki Dashboard, enabling LLMs to discover devices, check health, troubleshoot, and generate reports via natural language.
    MIT