Skip to main content
Glama

intelligence_get

Read a specific CVE record and optionally refresh it by fetching the official CNA data into cache. Supports evidence-first Android and iOS security audits.

Instructions

Read an exact CVE; refresh=true fetches its official CNA record into cache.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
cve_idYes
refreshNo

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv1.0.3

TDQS

A3.8/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description usefully discloses that refresh=true mutates state by fetching the official CNA record into a cache, which explains the otherwise surprising readOnlyHint=false on a tool whose description starts with "Read". It does not cover error behavior for unknown CVE IDs or rate limits, so it falls short of 5.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single front-loaded sentence with the primary action first and the optional flag's effect second. No filler, no redundancy, instantly scannable.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return values need not be described, and the non-obvious cache side effect of refresh is covered. The remaining gap is the accepted format/validation of cve_id, which an agent should not have to guess.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must carry parameter meaning. It explains refresh (fetches the CNA record into cache) but says nothing about cve_id format (e.g. CVE-YYYY-NNNN) or whether an unknown ID is an error, leaving one of two parameters undocumented.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource ("Read an exact CVE") and the word "exact" implicitly distinguishes it from the lookup-by-query sibling intelligence_search. It is clear what the tool does, but it never names the sibling it differs from, so differentiation is inferred rather than stated.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is only implied: "exact CVE" suggests this is the direct-ID path versus intelligence_search, and refresh=true is given a condition, but there is no explicit "use this when / use X instead" guidance and no statement of when to set refresh.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.