Skip to main content
Glama
ry-ops

fortigate-mcp-server

by ry-ops

get_firewall_policy

Retrieve a single FortiGate firewall policy by policy ID, with optional VDOM, to inspect rules, NAT, and security settings before changes.

Instructions

Get one firewall policy.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
vdomNoVDOM (default: FORTIGATE_VDOM, usually root)
policyidYesPolicy ID

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.4.1

TDQS

C2.9/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full behavioral burden, yet it only restates the operation. It does not disclose error behavior for an unknown policyid, required permissions, VDOM resolution behavior, or what the returned payload contains.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single short sentence with the operation front-loaded and zero padding. It is appropriately sized for a simple getter, though it is arguably terse to the point of under-specification.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a two-parameter read tool with full schema coverage and no output schema, the essentials are covered by the schema. Still, a getter should say what it returns and what happens on a missing policyid, neither of which is present.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, with policyid and the vdom default both documented in the schema, so the baseline is 3. The description adds no syntax, format, or lookup guidance beyond what the schema already supplies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (Get) and resource (firewall policy) with a scope qualifier (one), which distinguishes it from the plural list_firewall_policies sibling. However, it never names that sibling or otherwise differentiates itself from the other firewall_policy-family tools explicitly.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no statement of when to use this tool versus list_firewall_policies, get_policy_stats, or the mutation siblings, and no prerequisites or exclusions are given. The agent must infer that a single policy is fetched by ID.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.