Skip to main content
Glama
josimarh

azure-mcp-pilot

by josimarh

get_role_risk_score

Read-onlyIdempotent

Calculate a 0-100 risk score for a privileged Microsoft Entra ID or Azure RBAC role to prioritize audits and mitigate excessive access.

Instructions

Calcula score de risco (0-100) para uma role privilegiada de Entra ID ou Azure RBAC.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
roleYes
scopeNo/
stateNo
providerYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

C2.9/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true, idempotentHint=true, destructiveHint=false and openWorldHint=true, so the safety profile is covered. The description adds useful context with the 0-100 score range and the two supported providers, but says nothing about what drives the score, caching, or latency.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single front-loaded sentence with no filler; the score range and provider scope appear immediately. It is efficient, though the brevity comes partly from under-specification rather than tight editing.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, no annotation detail on return semantics, and 4 undocumented parameters, the description leaves an agent unable to determine valid provider values, how 'scope' and 'state' affect the result, or how to interpret the numeric score. For a tool with this parameter surface it does too little.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0% across 4 parameters, and the description only indirectly implies 'role' and 'provider' ('role privilegiada de Entra ID ou Azure RBAC'). The optional 'scope' (default '/') and 'state' parameters — including valid provider values and scope path format — are entirely undocumented in both description and schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (Calcula) and resource (score de risco) and scopes it to privileged roles in Entra ID or Azure RBAC, with an explicit 0-100 range. It is clearly distinguishable from sibling listing/assessment tools, though it does not name a sibling it replaces.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no when-to-use guidance, no prerequisites, and no routing to alternatives such as detect_toxic_combinations or compute_identity_blast_radius. The agent must infer that this is a per-role scoring call from the description alone.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools