Skip to main content
Glama
nh4ttruong

secobserve-mcp

Call SecObserve Action

secobserve_call_action
Destructive

Invoke any non-CRUD SecObserve action like apply_rules, simulate, or export observations when no dedicated tool covers it.

Instructions

Invoke a named non-CRUD action on a resource (apply_rules, copy, simulate, exports, ...).

This is the escape hatch for the long tail of SecObserve endpoints that are neither CRUD nor common enough to deserve their own tool. secobserve_list_resources lists every action with its verb and whether it needs an id. Actions that return a file are written to the server's export directory and the path is reported.

Prefer the dedicated tools where they exist: secobserve_assess_observation, secobserve_bulk_assess_observations, secobserve_approve_observation_log, secobserve_run_periodic_task. They validate the payload; this tool does not.

Args: resource (str): Resource owning the action. action (str): Action name (bare name, no slashes). id (Optional[int]): Required for detail actions, omitted for collection ones. body (Optional[dict]): JSON body for POST/PATCH actions. params (Optional[dict]): Query parameters for GET actions. method (Optional[str]): Override the default verb (only needed for product_notifications/override, which is POST to set and DELETE to clear). filename (Optional[str]): Base filename for file-returning actions. response_format (ResponseFormat): "markdown" or "json".

Returns: str: For JSON actions, the response body as markdown or JSON (a list response is rendered as items with pagination-style metadata, and a list too long for the result budget is cut to the rows that fit, with a "trimmed" block saying so; such a list is not paginated, so the rest is reachable only by narrowing the request). For file actions, a line giving the absolute path and byte size written. For empty 204 responses, a confirmation that the action was accepted.

Examples: - Use when: "re-apply rules to product 12" -> resource="products", action="apply_rules", id=12 - Use when: "how many observations would this rule match?" -> resource="general_rules", action="simulate", id=4, body={...rule definition...} - Use when: "export product 12's observations to Excel" -> resource="products", action="export_observations_excel", id=12 - Don't use when: a dedicated tool covers it (assessments, approvals, imports, scans, metrics, periodic tasks).

Error Handling: Unknown action -> error listing the resource's valid actions. Missing or stray id -> error saying which the action needs. Read-only mode blocks every non-GET action.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
idNoRecord id. Required for detail actions, must be omitted for collection actions.
bodyNoJSON request body, for POST/PATCH actions.
actionYesAction name as listed by secobserve_list_resources, e.g. 'apply_rules'.
methodNoOverride the action's default verb. Only 'product_notifications/override' needs this (POST or DELETE).
paramsNoQuery parameters, for GET actions.
filenameNoFor export actions that return a file: the base filename to write into the export directory. No directory separators. Defaults to '<resource>-<action>-<id>'.
resourceYesResource the action belongs to, e.g. 'products', 'license_policies'.
response_formatNo'markdown' for reading, 'json' for further processing.markdown

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed15 schema fields changedv0.3.0
    • removedInput schema / $defs / CallActionInput
      Removed value: -{
      -  "additionalProperties": false,
      -  "description": "Input model for invoking a named non-CRUD action.",
      -  "properties": {
      -    "action": {
      -      "description": "Action name as listed by secobserve_list_resources, e.g. 'apply_rules'.",
      -      "title": "Action",
      -      "type": "string"
      -    },
      -    "body": {
      -      "anyOf": [
      -        {
      -          "additionalProperties": true,
      -          "type": "object"
      -        },
      -        {
      -          "type": "null"
      -        }
      -      ],
      -      "default": null,
      -      "description": "JSON request body, for POST/PATCH actions.",
      -      "title": "Body"
      -    },
      -    "filename": {
      -      "anyOf": [
      -        {
      -          "maxLength": 120,
      -          "type": "string"
      -        },
      -        {
      -          "type": "null"
      -        }
      -      ],
      -      "default": null,
      -      "description": "For export actions that return a file: the base filename to write into the export directory. No directory separators. Defaults to '<resource>-<action>-<id>'.",
      -      "title": "Filename"
      -    },
      -    "id": {
      -      "anyOf": [
      -        {
      -          "minimum": 1,
      -          "type": "integer"
      -        },
      -        {
      -          "type": "null"
      -        }
      -      ],
      -      "default": null,
      -      "description": "Record id. Required for detail actions, must be omitted for collection actions.",
      -      "title": "Id"
      -    },
      -    "method": {
      -      "anyOf": [
      -        {
      -          "enum": [
      -            "GET",
      -            "POST",
      -            "PATCH",
      -            "DELETE"
      -          ],
      -          "type": "string"
      -        },
      -        {
      -          "type": "null"
      -        }
      -      ],
      -      "default": null,
      -      "description": "Override the action's default verb. Only 'product_notifications/override' needs this (POST or DELETE).",
      -      "title": "Method"
      -    },
      -    "params": {
      -      "anyOf": [
      -        {
      -          "additionalProperties": true,
      -          "type": "object"
      -        },
      -        {
      -          "type": "null"
      -        }
      -      ],
      -      "default": null,
      -      "description": "Query parameters, for GET actions.",
      -      "title": "Params"
      -    },
      -    "resource": {
      -      "description": "Resource the action belongs to, e.g. 'products', 'license_policies'.",
      -      "title": "Resource",
      -      "type": "string"
      -    },
      -    "response_format": {
      -      "$ref": "#/$defs/ResponseFormat",
      -      "default": "markdown",
      -      "description": "Output format."
      -    }
      -  },
      -  "required": [
      -    "resource",
      -    "action"
      -  ],
      -  "title": "CallActionInput",
      -  "type": "object"
      -}
    • addedInput schema / additionalProperties
      Added value: +false
    • addedInput schema / properties / action
      Added value: +{
      +  "description": "Action name as listed by secobserve_list_resources, e.g. 'apply_rules'.",
      +  "title": "Action",
      +  "type": "string"
      +}
    • addedInput schema / properties / body
      Added value: +{
      +  "anyOf": [
      +    {
      +      "additionalProperties": true,
      +      "type": "object"
      +    },
      +    {
      +      "type": "null"
      +    }
      +  ],
      +  "default": null,
      +  "description": "JSON request body, for POST/PATCH actions.",
      +  "title": "Body"
      +}
    • addedInput schema / properties / filename
      Added value: +{
      +  "anyOf": [
      +    {
      +      "maxLength": 120,
      +      "type": "string"
      +    },
      +    {
      +      "type": "null"
      +    }
      +  ],
      +  "default": null,
      +  "description": "For export actions that return a file: the base filename to write into the export directory. No directory separators. Defaults to '<resource>-<action>-<id>'.",
      +  "title": "Filename"
      +}
    • addedInput schema / properties / id
      Added value: +{
      +  "anyOf": [
      +    {
      +      "minimum": 1,
      +      "type": "integer"
      +    },
      +    {
      +      "type": "null"
      +    }
      +  ],
      +  "default": null,
      +  "description": "Record id. Required for detail actions, must be omitted for collection actions.",
      +  "title": "Id"
      +}
    • addedInput schema / properties / method
      Added value: +{
      +  "anyOf": [
      +    {
      +      "enum": [
      +        "GET",
      +        "POST",
      +        "PATCH",
      +        "DELETE"
      +      ],
      +      "type": "string"
      +    },
      +    {
      +      "type": "null"
      +    }
      +  ],
      +  "default": null,
      +  "description": "Override the action's default verb. Only 'product_notifications/override' needs this (POST or DELETE).",
      +  "title": "Method"
      +}
    • removedInput schema / properties / params / $ref
      Removed value: -"#/$defs/CallActionInput"
    • addedInput schema / properties / params / anyOf
      Added value: +[
      +  {
      +    "additionalProperties": true,
      +    "type": "object"
      +  },
      +  {
      +    "type": "null"
      +  }
      +]
    • addedInput schema / properties / params / default
      Added value: +null
    • addedInput schema / properties / params / description
      Added value: +"Query parameters, for GET actions."
    • addedInput schema / properties / params / title
      Added value: +"Params"
    • addedInput schema / properties / resource
      Added value: +{
      +  "description": "Resource the action belongs to, e.g. 'products', 'license_policies'.",
      +  "title": "Resource",
      +  "type": "string"
      +}
    • addedInput schema / properties / response_format
      Added value: +{
      +  "$ref": "#/$defs/ResponseFormat",
      +  "default": "markdown",
      +  "description": "'markdown' for reading, 'json' for further processing."
      +}
    • changedInput schema / required
      Previous value: -[
      -  "params"
      -]New value: +[
      +  "resource",
      +  "action"
      +]
  2. First observedv0.1.2

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Discloses critical behaviors beyond annotations: it does not validate payloads, read-only mode blocks non-GET actions, file-returning actions write to an export directory, and describes list trimming behavior. These are essential for safe usage and not present in annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is lengthy but well-organized with clear sections (Args, Returns, Examples, Error Handling). It front-loads the core purpose and provides necessary detail without redundancy. Could be trimmed slightly, but each sentence adds value.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a complex 8-parameter catch-all tool, the description covers every aspect: how to invoke, parameter semantics, return format (markdown/json, file paths, 204 confirmations), examples, and error handling. Nothing an agent needs to call it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

While the schema already covers all 8 parameters, the description adds practical guidance: id required for detail actions, body for POST/PATCH, params for GET, method override only for one specific case, filename for exports, and response_format for output type. This goes beyond the schema's basic descriptions.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's purpose: 'Invoke a named non-CRUD action on a resource' with examples like apply_rules, copy, simulate. It distinguishes itself from CRUD tools and dedicated action tools, making its role unambiguous.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly instructs when to use this tool: 'Prefer the dedicated tools where they exist' and lists them. Also provides concrete examples of when to use (e.g., re-apply rules, simulate) and when not to use (when a dedicated tool covers it).

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.