forensic-artifact-investigator
Server Quality Checklist
Latest release: v1.0.0
- Disambiguation5/5
Each tool targets a distinct forensic operation: file metadata and hashing, string extraction, and memory dump analysis. There is no overlap in their purposes, making selection unambiguous.
Naming Consistency4/5Tool names follow a clear verb_noun pattern: extract-metadata, extract-strings, analyze-memory-dump. The verbs differ (extract vs. analyze) but this is justifiable based on the action type, and the pattern is consistent throughout.
Tool Count4/5Three tools is on the lower end, but each tool covers a broad, substantial forensic category. The count is appropriate for a focused investigator server, though could be slightly expanded.
Completeness4/5The set covers core artifact investigation needs: metadata extraction (with MIME mismatch and hash), string/indicator extraction, and memory analysis. Minor gaps like disk image carving or network artifact analysis exist, but the major workflows are represented.
Average 4/5 across 3 of 3 tools scored.
See the Tool Scores section below for per-tool breakdowns.
- No community issues in the last 6 months
- 1 commit in the last 12 weeks
- No stable releases found
- No critical vulnerability alerts
- No high-severity vulnerability alerts
- No code scanning findings
- CI is passing
Add a LICENSE file by following GitHub's guide. Once GitHub recognizes the license, the system will automatically detect it within a few hours.
If the license does not appear after some time, you can manually trigger a new scan using the MCP server admin interface.
MCP servers without a LICENSE cannot be installed.
This repository includes a README.md file.
No tool usage detected in the last 30 days. Usage tracking helps demonstrate server value.
Tip: use the "Try in Browser" feature on the server page to seed initial usage.
Add a glama.json file to provide metadata about your server.
If you are the author, simply .
If the server belongs to an organization, first add
glama.jsonto the root of your repository:{ "$schema": "https://glama.ai/mcp/schemas/server.json", "maintainers": [ "your-github-username" ] }Then . Browse examples.
Add related servers to improve discoverability.
How to sync the server with GitHub?
Servers are automatically synced at least once per day, but you can also sync manually at any time to instantly update the server profile.
To manually sync the server, click the "Sync Server" button in the MCP server admin interface.
How is the quality score calculated?
The overall quality score combines two components: Tool Definition Quality (70%) and Server Coherence (30%).
Tool Definition Quality measures how well each tool describes itself to AI agents. Every tool is scored 1–5 across six dimensions: Purpose Clarity (25%), Usage Guidelines (20%), Behavioral Transparency (20%), Parameter Semantics (15%), Conciseness & Structure (10%), and Contextual Completeness (10%). The server-level definition quality score is calculated as 60% mean TDQS + 40% minimum TDQS, so a single poorly described tool pulls the score down.
Server Coherence evaluates how well the tools work together as a set, scoring four dimensions equally: Disambiguation (can agents tell tools apart?), Naming Consistency, Tool Count Appropriateness, and Completeness (are there gaps in the tool surface?).
Tiers are derived from the overall score: A (≥3.5), B (≥3.0), C (≥2.0), D (≥1.0), F (<1.0). B and above is considered passing.
Tool Scores
- Behavior3/5
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description provides some behavioral context: it reports 'bounded real string output' and includes a caveat that 'Indicators are not proof of malware.' However, it does not mention whether the operation is read-only, potential side effects, or limitations like large files.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Conciseness5/5Is the description appropriately sized, front-loaded, and free of redundancy?
Two concise sentences cover the command, output types, and a caveat. Every word serves a purpose; no redundancy or filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Completeness4/5Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple one-parameter tool with no output schema, the description adequately conveys the purpose, the nature of output (bounded strings plus indicators), and a necessary caution. It is moderately complete, though it omits usage guidance vs siblings.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Parameters3/5Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema has 0% description coverage, and the only parameter is filePath. The description adds minimal semantic context by referring to it as an 'evidence file,' but it does not clarify path requirements, file formats, or error behavior.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Purpose5/5Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action 'Run GNU strings -n 6 against an evidence file' with a specific command and target. It also mentions the output indicators, making it distinct from siblings like extract-metadata and analyze-memory-dump.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Usage Guidelines3/5Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage on evidence files but does not explicitly compare with alternative tools or specify when not to use this tool. It lacks a clear 'when to use this vs extract-metadata or analyze-memory-dump' statement.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
- Behavior4/5
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the behavioral burden and does well by stating it runs external analysis tools, calculates a hash, and interprets extension/MIME mismatches (including the crucial clarification that mismatches are not malware). However, it does not explicitly confirm side effects or permissions, which is a minor gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Conciseness5/5Is the description appropriately sized, front-loaded, and free of redundancy?
The description is concise, consisting of two sentences that front-load the primary actions and then add a key interpretive note. Every sentence earns its place, and there is no redundant or filler wording.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Completeness3/5Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The tool is relatively straightforward, but with no output schema and no annotations, the description does not explain what the tool returns (e.g., the hash value, MIME type, metadata fields) or error handling. It adequately covers the 'why' and the analytical interpretation but leaves the return value unspecified for the agent.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Parameters3/5Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema has one parameter (filePath) with no description, and schema coverage is 0%. The description references 'evidence file' which gives context to the parameter's role, but it does not explain format, constraints, or acceptable values beyond the schema's minLength. This partially compensates but leaves room for improvement.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Purpose5/5Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly specifies the tool's function: run real file and ExifTool analysis, calculate SHA-256, and compare extension with MIME type. This distinguishes it from sibling tools like extract-strings and analyze-memory-dump by outlining unique actions and the analytical goal.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Usage Guidelines4/5Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies use for forensic evidence files needing metadata extraction and file-type discrepancy checks. It provides clear context but does not explicitly mention alternatives or exclusion scenarios, so it stops short of a 5.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
- Behavior4/5
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already indicate read-only and non-destructive behavior, so the bar is lower. The description adds valuable context: 'bounded' suggests limits, 'real Volatility analysis' clarifies it is genuine analysis, 'Returns plugin-level failures honestly' discloses error handling, and 'malfind hits require analyst review' alerts the user to follow-up needed.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Conciseness5/5Is the description appropriately sized, front-loaded, and free of redundancy?
Two concise sentences deliver all essential information with no filler. Key points are front-loaded: what it does, where it operates, and notable behaviors (honest failures, analyst review).
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Completeness4/5Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's simplicity (single parameter, no output schema) and good annotations, the description covers the essential context: scope, location, behavior on failures, and analyst involvement. It does not describe the return format, but the absence of an output schema may make that less critical.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Parameters3/5Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema description covers 100% of the parameter (filePath) with its own description, so the baseline is 3. The tool description reinforces 'Windows memory dump' and 'evidence root', which slightly supplements the schema, but does not add new semantic details beyond what is already provided.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Purpose5/5Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states a specific action ('Perform bounded, real Volatility analysis') on a specific resource ('Windows memory dump inside the evidence root'). It distinguishes itself from sibling tools by focusing on memory dump analysis rather than metadata or string extraction.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Usage Guidelines4/5Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides clear context: it applies to Windows memory dumps within the evidence root. It also hints at suitable scenarios by noting that failures are returned honestly and malfind hits require analyst review. However, it does not explicitly compare with sibling tools or state when not to use it.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
GitHub Badge
Glama performs regular codebase and documentation scans to:
- Confirm that the MCP server is working as expected.
- Confirm that there are no obvious security issues.
- Evaluate tool definition quality.
Our badge communicates server capabilities, safety, and installation instructions.
Card Badge
Copy to your README.md:
Score Badge
Copy to your README.md:
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/guyoverclocked/forensic-analyzer-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server