Skip to main content
Glama

harden_services

Disable insecure services like telnet, ftp, and www on MikroTik routers, and restrict SSH/Winbox management to specified subnets. Supports dry-run and rollback.

Instructions

Common hardening. disable_services default: telnet, ftp, www, api, api-ssl (SSH and Winbox stay on; SSH can never be disabled here). restrict_mgmt_to: subnets allowed to use SSH/Winbox (ask the user), comma-separated, '/prefix' or dotted mask. Refused if this computer's IP is not inside them.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameNorouter
dry_runNo
disable_upnpNo
disable_servicesNo
restrict_mgmt_toNo
rollback_minutesNo
ssh_strong_cryptoNo
mac_access_lan_onlyNo
disable_socks_proxy_bwtestNo
neighbor_discovery_lan_onlyNo

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.2.0

TDQS

C2.8/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full behavioral burden, and it does disclose two genuinely useful traits: SSH can never be disabled here, and restrict_mgmt_to is refused if this machine's IP is outside the listed subnets. However it says nothing about the mutation/rollback nature of the operation (rollback_minutes defaults to 5), permission needs, or what happens to the other eight flags.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three dense clauses, no filler, and the most consequential constraint (SSH/Winbox staying on) is stated up front. Tightly written for the amount of parameter-relevant information it packs in.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 10-parameter configuration-changing tool with no annotations, the description leaves major gaps: rollback behavior, the meaning of dry_run, and eight boolean flags are undocumented. An output schema exists so return values needn't be described, but the mutation-safety picture is incomplete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0% across 10 parameters, so the description must compensate. It does so well for disable_services (explicit default list) and restrict_mgmt_to (comma-separated, '/prefix' or dotted mask, with a refusal condition), but leaves eight parameters – including the safety-relevant rollback_minutes and dry_run – entirely unexplained.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose3/5

Does the description clearly state what the tool does and how it differs from similar tools?

"Common hardening" names a broad activity rather than a specific verb+resource, but the disable_services and restrict_mgmt_to clauses make the actual effect (disable named services, restrict management subnets) inferable. It never distinguishes itself from close siblings such as firewall_baseline or audit_security, so an agent cannot tell which one is appropriate without more context.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no when-to-use guidance and no comparison with firewall_baseline or audit_security, which appear to be the nearest alternatives. The only usage-like statement is "ask the user" for restrict_mgmt_to, which is a narrow interaction hint rather than selection guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.