Skip to main content
Glama

get_scope_exclusions

Retrieve out-of-scope categories a HackerOne program excludes from rewards by providing its handle. Use this to identify ineligible vulnerability classes.

Instructions

Report categories the program excludes from rewards (out-of-scope classes).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
handleYes

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

C2.8/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full behavioral burden. It implies a read-only lookup but says nothing about permissions, whether results are program-specific, rate limits, or freshness. With an output schema present, return-shape disclosure is not required, but the remaining behavioral context is thin.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single front-loaded sentence with no filler. The parenthetical clarifying 'out-of-scope classes' is the only elaboration, and it earns its place; nothing is wasted, though there is very little content overall.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With one parameter and a present output schema, the definition is nearly sufficient: it says what is returned. However, it omits what 'handle' identifies and how this list differs from the scope data returned by get_structured_scopes, leaving a genuine routing gap for an agent.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 0% and the sole parameter 'handle' is never mentioned in the description. The agent must infer that handle means a program handle and how it relates to the exclusions returned. The description does not compensate for the schema gap.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific resource and scope: categories excluded from rewards (out-of-scope classes). The verb 'Report' is slightly odd for a getter, and it does not explicitly distinguish itself from nearby siblings like get_structured_scopes or check_in_scope, but the purpose is clear and unambiguous.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no when-to-use guidance, no prerequisites, and no named alternative. An agent reading this cannot tell whether to call it instead of get_structured_scopes or check_in_scope, which is exactly the confusion this tool needs to resolve.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.