Skip to main content
Glama

Verify the Mandare ledger

mandare_verify
Read-only

Verify a signed, hash-chained Mandare ledger by checking hash chain, signatures, tree head, spend trail, budget replay, approvals, and revocation; optionally validate against witness history.

Instructions

Verify the local ledger: hash chain, door signatures, RFC 6962 tree head, spend trail and budget-counter replay, approval trail, and revocation state. With check_witness=true also checks the chain against the externally witnessed head history (catches truncation and rewrites). Returns the machine-readable verification report. Read-only.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
check_witnessNoAlso verify against the configured witness (detects truncation/rewrites)

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true, and the description aligns ('Read-only'), so no contradiction. Beyond the annotation it adds real behavioral value: it names the specific verification checks performed, states that the witness mode detects truncation and rewrites, and notes the output is a machine-readable report. It does not cover failure semantics (what a negative report looks like) or any auth requirements, keeping it out of 5 territory.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences, front-loaded with the core action and the scope of checks, followed by the conditional behavior and return note. The enumerated check list is dense but each item is meaningful. Slightly heavy packing into a single long sentence keeps it from a 5.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description carries the return-value burden and does so adequately ('Returns the machine-readable verification report'). For a zero-required-parameter verification tool with full schema coverage and a readOnly annotation, this is close to complete; only failure/error reporting specifics are absent.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% and there is only one optional boolean, so the schema already documents check_witness fully. The description's phrasing ('catches truncation and rewrites') largely restates the schema's own parenthetical, adding little new syntax or semantics. Baseline 3 is appropriate when the schema carries the parameter documentation.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb+resource ('Verify the local ledger') and enumerates exactly what is verified: hash chain, door signatures, RFC 6962 tree head, spend trail, budget-counter replay, approval trail, revocation state. This scope is precise enough to distinguish it from siblings like mandare_certify or mandare_gateway_health, which are attesting/health tools rather than ledger verifiers.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It clearly states the condition that changes behavior: set check_witness=true to verify against the externally witnessed head history and catch truncation/rewrites. That is actionable when-to-use guidance for the single parameter. It stops short of naming alternate tools (e.g., when to prefer mandare_certify) or stating when verification is unnecessary, so it falls short of a 5.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.