Skip to main content
Glama
cliwant

mcp-sam-gov

fac_search_audits

Read-only

Search Federal Audit Clearinghouse summaries by UEI, state, audit year, or amount expended to identify entity audit risk for subcontractor vetting.

Instructions

Search entity Single Audit summaries from the Federal Audit Clearinghouse (keyless via api.data.gov DEMO_KEY; api.fac.gov PostgREST general table) — the SUBCONTRACTOR / teaming AUDIT-RISK vetting entry point (2 CFR 200 Subpart F / Single Audit Act; every entity expending ≥$750K/yr in federal awards). Filters (all optional, AND-combined): auditeeUei (12-char SAM UEI — PRIMARY join key to SAM/USAspending/EDGAR), auditeeState (2-letter), auditYear (int), totalExpendedMin/totalExpendedMax (USD). limit (≤100, def 25), offset. Returns { audits:[{ report_id, auditee_uei, audit_year, auditee_name, auditee_ein, auditee_state, auditee_city, total_amount_expended, fac_accepted_date }] } + honest _meta. Feed report_id (or UEI) to fac_get_findings for the audit-RISK flags. ★PII: a HARDCODED select-allowlist surfaces ONLY entity + audit-summary fields and DELIBERATELY EXCLUDES personal-contact columns — NO caller select/column param. HONESTY: totalAvailable is the EXACT Content-Range total (a response header under Prefer:count=exact; '*'/absent/non-numeric denominator → totalAvailable:null + page-fullness hedge, NEVER 0); total_amount_expended is null-never-0; a bad column → PostgREST 400 → invalid_input (filtersDropped ALWAYS empty); genuine [] → honest empty; 400/403/5xx/timeout/HTML/non-array THROW. NOT a debarment/exclusion/fitness determination — cross-check SAM + OFAC. Keyless-first via DEMO_KEY (~10 req/hr shared; set DATA_GOV_API_KEY for production — never logged).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
limitNoRows per page, 1..100, default 25.
offsetNo0-based row offset for pagination (default 0).
auditYearNoFilter by audit year (int, → audit_year=eq.). e.g. 2024.
auditeeUeiNoFilter by 12-char SAM UEI (^[A-Z0-9]{12}$; → auditee_uei=eq. — the PRIMARY join key to SAM/USAspending/EDGAR). e.g. 'ZQGGHJH74DW7'.
auditeeStateNoFilter by 2-letter US state code (uppercase; → auditee_state=eq.). e.g. 'CA'.
totalExpendedMaxNoMaximum total federal awards expended (USD, → total_amount_expended=lte.).
totalExpendedMinNoMinimum total federal awards expended (USD, → total_amount_expended=gte.).

Schema Changelog

Changes observed during successful MCP inspections.

  1. Addedv1.12.0

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the readOnlyHint and openWorldHint annotations, the description discloses extensive behavioral traits: hardcoded select-allowlist excluding PII, honest totalAvailable semantics (exact Content-Range, null handling), null-never-0 for total_amount_expended, precise error handling (PostgREST 400 → invalid_input, filtersDropped always empty, genuine [] → honest empty, throws on various failures), keyless usage via DEMO_KEY with rate limits, and production key guidance. No contradiction with annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is dense and lengthy, but every sentence carries value: purpose, context, filters, return shape, honesty guarantees, error behavior, and authentication notes. It is front-loaded with purpose and context, then details follow logically. While not succinct, it is well-structured and justified for the tool's complexity.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the 7 parameters and no output schema, the description compensates by specifying the exact return JSON structure (audits array with fields) and the _meta object. It also explains error semantics, pagination (limit/offset), the primary join key, and cross-reference guidance. Nothing essential is missing for an agent to call this tool correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% with detailed descriptions for each parameter. The description adds meaningful context: filters are AND-combined, limit capped at 100 (def 25), offset explained, and auditeeUei identified as the PRIMARY join key to SAM/USAspending/EDGAR. This goes beyond the schema but does not introduce new syntax, so a 4 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool searches entity Single Audit summaries from the Federal Audit Clearinghouse, with a specific context (subcontractor/teaming audit-risk vetting) and explicit filters. It distinguishes itself from sibling fac_get_findings by directing the user to feed report_id or UEI to that tool for audit-RISK flags, ensuring no ambiguity.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It explicitly states this is the entry point for audit-risk vetting, explains when to use it (searching entity audit summaries), and provides exclusions: 'NOT a debarment/exclusion/fitness determination — cross-check SAM + OFAC.' It also directs the user to fac_get_findings for follow-up, leaving no doubt about alternative tools or conditions.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools