Skip to main content
Glama

rush_sbom

Generate an SBOM for a project and save it to an explicit output path. If cdxgen is absent, status is 'skipped'. Use flags for network, build, overwrite, or slow.

Instructions

Generate an SBOM only to a safe explicit output path; missing cdxgen returns status='skipped'.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
pathYes
overwriteNo
allow_slowNo
allow_buildNo
output_pathNo
allow_browserNo
allow_networkNo
allow_downloadNo
allow_cache_writeNo
allow_artifact_writeNo

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
rawNo
toolNo
engineNo
statusNo
metricsNo
summaryNo
findingsNo
metadataNo
artifactsNo
duration_msNo
review_kindNo
engine_versionNo
review_providerNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changedv0.2.2
    • changedOutput schema / properties / metrics / anyOf
      Previous value: -[
      -  {
      -    "additionalProperties": {
      -      "anyOf": [
      -        {
      -          "type": "integer"
      -        },
      -        {
      -          "type": "number"
      -        },
      -        {
      -          "type": "string"
      -        }
      -      ]
      -    },
      -    "type": "object"
      -  },
      -  {
      -    "type": "null"
      -  }
      -]New value: +[
      +  {
      +    "additionalProperties": {
      +      "anyOf": [
      +        {
      +          "type": "integer"
      +        },
      +        {
      +          "type": "number"
      +        },
      +        {
      +          "type": "string"
      +        },
      +        {
      +          "type": "null"
      +        }
      +      ]
      +    },
      +    "type": "object"
      +  },
      +  {
      +    "type": "null"
      +  }
      +]
  2. First observedv0.3.0

TDQS

B3.2/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description must disclose behavioral traits. It does mention a key fallback: 'missing cdxgen returns status='skipped'' – valuable. It also implies a safety constraint on output path. However, it does not clarify behaviors around the many boolean flags (overwrite, allow_*), nor what happens if output_path is null, nor the exact output structure. The disclosure is partial, earning a 3.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single sentence, front-loaded with the primary action. It is highly concise with no filler. The structure is efficient, though it sacrifices completeness for brevity – but that tradeoff is evaluated in other dimensions.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness1/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given 10 parameters, no annotations, 0% schema coverage, and no output schema visible, this description is woefully incomplete. It does not explain parameter semantics, output format, failure modes beyond one case, or usage context. An agent would struggle to call this tool correctly without further information.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must compensate. It only touches on output_path via the safety phrase, but does not explain any of the 10 parameters. The booleans like overwrite, allow_slow, allow_build, etc., are completely unexplained. This is insufficient for an agent to correctly set parameters.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the action: 'Generate an SBOM' – a specific verb and resource. It also adds a meaningful constraint ('only to a safe explicit output path') that differentiates it from generic SBOM tools. While no sibling is named, the purpose is unambiguous and distinct within the rush_* family.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides no guidance on when to use this tool versus alternatives. It does not mention any other tool, prerequisites, or conditions for selection. The only hint is the implicit need for an SBOM, but that is not explicit enough to count as usage guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.