Skip to main content
Glama

http_headers_audit

Fetch a URL and evaluate security headers like HSTS, CSP, and cookie flags, scoring policy quality rather than mere presence. Identify misconfigurations without retrieving the body.

Instructions

Fetch a URL in scope and evaluate its security headers (HSTS, CSP, X-Content-Type-Options, Referrer-Policy, CORS, cookie flags), scoring the QUALITY of each policy rather than its mere presence. The body is not retrieved. Does NOT test exploitability. Cost: 1 quota unit.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
urlYesAbsolute http(s) URL in scope.
follow_redirectsNoFollow in-scope redirects before auditing.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
urlYes
gradeNo
scoreNo
statusYes
findingsNo
pinned_ipNo
missing_headersNo
present_headersNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden and does well: it discloses scope enforcement, that the body is not retrieved, that exploitability is not tested, and a concrete cost of 1 quota unit. It omits finer traits like redirect/auth behavior or rate limits, but covers the important safety and cost profile.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences, each front-loading the important facts: what is audited, what is deliberately excluded, and the cost. No repetition or filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return values need no explanation. The description is complete enough for a scoped, non-destructive audit tool, though it could state redirect handling behavior and the explicit alternative (http_fetch) to be fully self-sufficient.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so both parameters (url, follow_redirects) are already documented in the schema. The description only echoes the in-scope constraint already stated in the url parameter, adding no syntax or format detail beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (evaluate security headers), the resource (a URL in scope), and enumerates the exact header classes checked (HSTS, CSP, X-Content-Type-Options, Referrer-Policy, CORS, cookie flags). It also draws a sharp boundary against sibling http_fetch by stating 'The body is not retrieved,' so an agent can distinguish the two without opening either schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives clear context for use ('Fetch a URL in scope and evaluate its security headers') and a when-not ('Does NOT test exploitability'), which steers the agent away from expecting active testing. It stops short of explicitly naming http_fetch as the alternative when the body IS needed, leaving that inference to the reader.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.