Skip to main content
Glama

network_rules

Idempotent

Manage network requests in Chrome by blocking, redirecting, modifying headers, stubbing responses, and recording/replaying API traffic with forced errors or delays.

Instructions

Network interception, browser-wide, survives reloads until cleared: block, redirect, set/remove headers, stub a synthetic body, or record real API responses and replay them with forced errors/latency (local helper; from HTTPS pages the stub host must be trusted).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
bodyNoResponse body (action=stub)
nameNoFixture name for record/replay
actionYesrecord saves the page's API responses (url_filter) as a fixture, replay serves them with overrides; list/clear
headerNoHeader name for action=modify_header, e.g. "User-Agent"
statusNoaction=stub
overridesNoreplay: force a status, body or delay on matching URLs — error states a real backend will not produce
url_filterNodeclarativeNetRequest urlFilter, e.g. "||example.com/api/*"
content_typeNoaction=stubapplication/json
header_valueNoOmit to remove header
redirect_urlNoDestination for action=redirect
header_targetNoresponse = strip content-security-policy / x-frame-options, inject CORSrequest
resource_typesNoLimit the rule to these request types; omitted = all of them

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed4 schema fields changedv1.16.1
    • changedInput schema / properties / action / description
      Previous value: -"list and clear inspect and drop the rules already installed"New value: +"record saves the page's API responses (url_filter) as a fixture, replay serves them with overrides; list/clear"
    • changedInput schema / properties / action / enum
      Previous value: -[
      -  "block",
      -  "redirect",
      -  "modify_header",
      -  "stub",
      -  "list",
      -  "clear"
      -]New value: +[
      +  "block",
      +  "redirect",
      +  "modify_header",
      +  "stub",
      +  "record",
      +  "replay",
      +  "list",
      +  "clear"
      +]
    • addedInput schema / properties / name
      Added value: +{
      +  "description": "Fixture name for record/replay",
      +  "type": "string"
      +}
    • addedInput schema / properties / overrides
      Added value: +{
      +  "description": "replay: force a status, body or delay on matching URLs — error states a real backend will not produce",
      +  "items": {
      +    "properties": {
      +      "body": {
      +        "type": "string"
      +      },
      +      "latency_ms": {
      +        "type": "number"
      +      },
      +      "status": {
      +        "type": "number"
      +      },
      +      "url_contains": {
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "url_contains"
      +    ],
      +    "type": "object"
      +  },
      +  "type": "array"
      +}
  2. Changed4 schema fields changedv1.10.0
    • addedInput schema / properties / action / description
      Added value: +"list and clear inspect and drop the rules already installed"
    • addedInput schema / properties / header / description
      Added value: +"Header name for action=modify_header, e.g. \"User-Agent\""
    • addedInput schema / properties / redirect_url / description
      Added value: +"Destination for action=redirect"
    • addedInput schema / properties / resource_types / description
      Added value: +"Limit the rule to these request types; omitted = all of them"
  3. First observedv1.8.0

TDQS

A3.5/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description discloses that rules persist across reloads until cleared and that it is a local helper, with an HTTPS-specific limitation. Combined with annotations indicating non-read-only, idempotent behavior, this gives a solid picture of side effects.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is compact and dense, packing many capabilities into a single readable paragraph. It avoids fluff, though the long colon-separated list requires careful parsing.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

It covers core behavior and constraints, but does not explain return values, rule precedence, how to clear a single rule versus all rules, or how overlapping rules are resolved. For a tool with this many actions and optional parameters, that is a notable gap.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The JSON schema already documents all parameters with descriptions, and the narrative description adds useful semantics such as header_target behavior for stripping CSP and injecting CORS, and overrides being useful for error states a real backend will not produce.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly identifies the tool as browser-wide network interception that can block, redirect, set/remove headers, stub, record, and replay. It is distinct from monitoring tools like monitor_network, though it does not use an explicit verb phrase like 'Manage network rules'.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explains what the tool can do but gives no guidance on when to use it versus alternatives such as monitor_network or http_request. The HTTPS host trust caveat is useful but does not provide selection criteria.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.