Skip to main content
Glama
kasireddy-sec

Tenable Security MCP

get_tenable_cloud_asset

Retrieve detailed information for a Tenable Vulnerability Management asset by its UUID to support vulnerability triage and remediation planning.

Instructions

Get details for a Tenable Vulnerability Management asset.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
asset_uuidYes

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

C2.8/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full behavioral burden. 'Get details' weakly implies a read-only operation, but nothing states permissions/auth requirements, rate limiting, or behavior when the UUID is unknown or the asset is inaccessible. An output schema exists, so return shaping is partly covered, but the safety/behavior profile is not.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single tight sentence with no wasted words and the purpose front-loaded. It is efficient, though the brevity is part of why other dimensions are under-specified.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a simple single-UUID lookup with an existing output schema, the essentials are thin but workable. Missing details such as error behavior for invalid/absent UUIDs and the source of the UUID keep it at minimum-viable completeness.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0% and the single required parameter asset_uuid has no documentation in either schema or description. The description's mention of 'asset' only weakly ties to the parameter; it adds no format, source, or validity guidance for the UUID.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (Get) and resource (Tenable Vulnerability Management asset), and 'details' implies single-entity retrieval, implicitly distinguishing it from the sibling list_tenable_cloud_assets. It does not, however, explicitly name that sibling or clarify scope boundaries.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no when-to-use guidance, no mention of prerequisites or prerequisites like owning a valid asset_uuid, and no named alternative (e.g., list_tenable_cloud_assets for enumeration). The agent must infer usage entirely from the name.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.