Skip to main content
Glama
ry-ops

fortigate-mcp-server

by ry-ops

list_app_control_profiles

List application control profiles with their rules, showing application and category names instead of IDs. Filter results by profile name or VDOM.

Instructions

App-control profiles with their rules, showing application and category names instead of ids.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameNoOnly this profile
vdomNoVDOM (default: FORTIGATE_VDOM, usually root)

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.4.1

TDQS

B3.2/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden. It does disclose one genuinely useful behavioral trait — application and category names are resolved instead of raw ids — but says nothing about read-only safety, pagination, result size, or whether unset filters return everything.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single short clause with zero filler, and the name-resolution behavior is stated up front. It is arguably too terse rather than padded, so it loses a point only for under-specification rather than verbosity.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a two-parameter, no-annotation, no-output-schema list tool, the description covers the core intent but omits return-shape expectations and the read-only nature. It is minimally adequate rather than complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so both parameters (name, vdom) are already documented in the schema, establishing a baseline of 3. The description adds no parameter-level detail such as what happens when name is omitted or how vdom defaults interact.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The fragment names the exact resource (app-control profiles) and states what each entry contains (their rules), which is enough for an agent to distinguish it from siblings like add_app_control_rule or list_app_categories. It is a noun phrase with no explicit verb ('List') and does no explicit sibling routing, so it falls short of a 5.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no when-to-use guidance, no mention of prerequisites, and no routing to alternatives such as add_app_control_rule or delete_app_control_rule. The only implicit signal is that it is a read operation, which the agent must infer from the name.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.