Skip to main content
Glama
reliai-in

io.github.loopg/pramana-mcp

by reliai-in

verify_bundle

Validate a Pramana signed evidence bundle offline using a bundle path and public key path; no account or network access is required.

Instructions

Verify a Pramana signed evidence bundle offline, with no account and no network access.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
bundle_pathYes
public_key_pathYes

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.3

TDQS

B3.3/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden, and it does disclose two meaningful behavioral traits: the operation is fully offline and requires no account or network. It stops short of explaining what a failed verification does (error vs. negative result), whether it validates signature only or the full chain, or any resource constraints.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single sentence that front-loads the action and qualifies it with the two operationally important constraints. No filler or redundancy.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return-value explanation is not required, and the offline/no-account context is a useful addition. The gap is on the input side: with zero schema coverage, the description leaves the caller without any notion of what the two paths should point to.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0% and both required parameters (bundle_path, public_key_path) are bare strings with no titles beyond the property name. The description mentions a 'signed evidence bundle' but never explains that these are filesystem paths, what format the bundle or key should be in, or how they relate to each other.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description names a specific verb (verify) and resource (a Pramana signed evidence bundle), so there is no ambiguity about what the tool does. It is clearly distinct from the trace/diff listing siblings, though it does not explicitly contrast itself with them.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The phrase 'offline, with no account and no network access' implies the conditions under which this tool is appropriate (air-gapped or credential-free verification). However, it never states when to prefer this over other verification paths or what preconditions the caller must satisfy beyond having the two files.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.