mcp-guarded-tools
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| MCP_RATE_MAX | No | Maximum number of calls per 10-second sliding window for rate limiting. Defaults to '5'. | 5 |
| MCP_AUDIT_LOG | No | Path to the audit log file. If not set, an in-memory audit log is used. | |
| MCP_TENANT_ID | No | Tenant ID for the session. Defaults to 'acme'. | acme |
| MCP_MAX_REQUESTS | No | Maximum number of requests for the session budget. Defaults to '50'. | 50 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| search_toolsA | Find domain tools by keyword. Returns name, domain, one-line summary and whether the tool mutates state. Use this instead of expecting every tool to be listed up front. |
| describe_toolA | Return the full description and JSON Schema for one tool discovered via search_tools. |
| confirm_actionA | Issue a single-use, time-limited confirmation token for a mutating tool. The token is bound to the exact arguments supplied here: they must match the later invoke_tool call. |
| invoke_toolA | Run a domain tool by name. Arguments are validated against the tool schema. Mutating tools additionally require confirmation_token. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 4 tools
Each tool has a clearly distinct role: discovery (search_tools), inspection (describe_tool), authorization (confirm_action), and execution (invoke_tool). No overlap or ambiguity exists between their purposes.
All tool names follow the same verb_noun pattern with underscores (search_tools, describe_tool, confirm_action, invoke_tool). The naming is perfectly consistent and predictable.
With 4 tools, the set is tightly scoped for a proxy/guardian layer. Each tool earns its place and there is no bloat or missing essential step in the workflow.
The tool set covers the complete lifecycle: discovery, detail inspection, confirmation for mutations, and invocation. There are no obvious gaps; the guard mechanism is fully realized.