Skip to main content
Glama

delimit_security_ingest

Ingest JSON output from security scanners like Trivy, Semgrep, and CodeQL. Normalize findings into a canonical schema and track in ledger to gate deployments on unresolved critical issues.

Instructions

Ingest security scan results from external tools (Pro).

Accepts JSON output from Trivy, Semgrep, npm audit, pip-audit, Snyk, or CodeQL. Normalizes findings into a canonical schema, tracks in the ledger, and enables deploy gating on unresolved criticals.

This is the orchestrator model - Delimit doesn't run the scanner, it adds intelligence on top of results you already have.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
toolYesScanner name (trivy, semgrep, npm-audit, pip-audit, snyk, codeql).
resultsYesJSON string of scan results, or path to a JSON results file.
repoNoRepository identifier (e.g. "my-org/my-repo"). Auto-detects if empty.
commit_shaNoGit commit SHA the scan was run against. Auto-detects if empty.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden. It discloses that it accepts JSON, normalizes findings, tracks in ledger, and enables deploy gating. It lacks details on potential side effects or error behavior, but the core behavioral traits are adequately covered. A small deduction for not mentioning idempotency or write implications.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is concise and well-structured: a headline verb phrase, a list of supported tools, and a clear explanatory sentence. Every sentence adds value, and the most critical information is front-loaded.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool has an output schema and 4 parameters, the description sufficiently covers input handling, normalization, ledger tracking, and deploy gating. No significant gaps remain for an agent to understand the tool's overall functionality.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% with descriptive parameter descriptions. The description adds only minor value beyond the schema, such as noting that repo and commit_sha auto-detect if empty. For high-coverage schema, the baseline is 3, and the description does not significantly surpass that.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool ingests security scan results, lists supported external tools (Trivy, Semgrep, etc.), and explains its role as an orchestrator that normalizes findings and enables deploy gating. It distinguishes itself from siblings like delimit_security_scan by explicitly noting it doesn't run the scanner.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly states this is the orchestrator model and that Delimit adds intelligence on top of results you already have, implying it should be used when you have existing scan results from supported tools, not for running scanners themselves. This clears directs the agent on when to use this tool versus running a scanner.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Install Server

Other Tools

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/delimit-ai/delimit-mcp-server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server