Skip to main content
Glama
godzeo
by godzeo

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Server capabilities have not been inspected yet.

Tools

Functions exposed to the LLM to take actions

NameDescription
http_getC

HTTP GET request with full support (headers, cookies, body, timeout) - All requests logged

http_postC

HTTP POST request with full support (headers, cookies, body, timeout) - All requests logged

http_putC

HTTP PUT request with full support (headers, cookies, body, timeout) - All requests logged

http_deleteC

HTTP DELETE request with full support (headers, cookies, body, timeout) - All requests logged

http_patchC

HTTP PATCH request with full support (headers, cookies, body, timeout) - All requests logged

http_headC

HTTP HEAD request with full support (headers, cookies, timeout) - All requests logged

http_optionsC

HTTP OPTIONS request with full support (headers, cookies, timeout) - All requests logged

http_raw_requestA

šŸ”’ CRITICAL SECURITY TESTING TOOL: Sends HTTP requests with ABSOLUTE PRECISION - All requests logged

āš ļø IMPORTANT: This tool preserves EVERY SINGLE CHARACTER of your request:

  • Headers: Every cookie, token, session ID - NO CHARACTER LIMIT, NO TRUNCATION

  • Body: Raw payload sent byte-for-byte, preserving payloads exactly

  • Cookies: Complete cookie strings including long JWT tokens, session data

  • Special characters: ', ", , %, &, =, etc. are preserved without encoding

  • Whitespace: Spaces, tabs, newlines maintained exactly as provided

šŸŽÆ Perfect for: all kinds of security vulnerability testing, testing like SQL injection, XSS, CSRF, authentication bypass, parameter pollution šŸ“ Guarantee: What you input is EXACTLY what gets sent - zero modifications šŸ“Š All requests and responses are automatically logged to ~/mcp_requests_logs/

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.5/5.0

Scored across 8 tools

Disambiguation5/5

Each tool has a clearly distinct purpose: seven tools correspond to specific HTTP methods (GET, POST, etc.), while the eighth tool (http_raw_request) is explicitly for security testing with absolute precision. There is no ambiguity or overlap between the standard HTTP method tools, and the security tool is clearly differentiated by its specialized function.

Naming Consistency5/5

All tool names follow a consistent snake_case pattern with the prefix 'http_' followed by the HTTP method name (e.g., http_get, http_post) or a descriptive term (http_raw_request). This uniformity makes the tools easily predictable and readable, with no deviations in naming conventions.

Tool Count5/5

With 8 tools, the set is well-scoped for an HTTP requests server. It covers all standard HTTP methods (GET, POST, PUT, DELETE, PATCH, HEAD, OPTIONS) plus a specialized security testing tool, which is a reasonable and complete set for the domain without being excessive or insufficient.

Completeness5/5

The tool surface is complete for the domain of HTTP requests. It provides full CRUD-like coverage with all standard HTTP methods, and the inclusion of http_raw_request adds specialized functionality for security testing, ensuring no gaps in core operations or advanced use cases.

Maintenance

ActivityInactive
ResponsivenessNo issues