Skip to main content
Glama

list_programs

Retrieve HackerOne programs you can access, filtered by bounty eligibility, submission state, or name, and return handles for use in other tools.

Instructions

List HackerOne programs you can access. Filter by bounty eligibility, submission state or a handle/name substring. Returns handles to feed the other tools.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
pageNo
limitNo
queryNo
offers_bountiesNo
submission_stateNo

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A3.8/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the disclosure burden. 'List' and 'programs you can access' imply a permission-scoped read, but the description says nothing about pagination behavior, rate limits, or the result shape beyond handles. Adequate but thin for a tool with zero annotation coverage.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three tight sentences, front-loaded with the core action, then filters, then the return-value purpose. No redundant or wasted phrasing.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return values need not be re-explained, and the description correctly points to handles as the takeaway. The remaining gap is undocumented pagination parameters and the absence of any behavioral notes for a tool with no annotations.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must compensate, and it does so only partially: it explains query (handle/name substring), offers_bounties (bounty eligibility) and submission_state, but says nothing about the page and limit pagination parameters the schema exposes.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('List HackerOne programs') and adds scope ('you can access'), which lets an agent distinguish it from the singular get_program sibling. It does not explicitly name or contrast with siblings, but the list-vs-get distinction is implicit.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives clear context: filter by bounty eligibility, submission state, or a handle/name substring, and the closing line 'Returns handles to feed the other tools' signals the downstream workflow. No explicit when-not or alternative-tool routing, so it stops short of a 5.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.