Skip to main content
Glama
threadlinqs-cmd

Intel Threadlinqs MCP

Resolve Canonical Name

resolve_entity
Read-onlyIdempotent

Resolve aliases to canonical threat entity names and UUIDs, enabling accurate pivoting across intelligence tools. Specify entity type to narrow lookups.

Instructions

Normalize an actor / malware / tool / sector / region / technique name or alias to its canonical reference form + stable UUID (e.g. "fancy bear" → "APT28"). Call this BEFORE pivoting (get_actor / get_malware_intelligence / get_tool_intelligence / search_threats) when unsure of the canonical name. Optional type narrows the lookup.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameYesName or alias to resolve
typeNoOptional: actor|malware|tool|sector|region|technique|campaign

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
uuidNo
queryYes
matchedYes
canonicalNoCanonical name — feed to get_actor / get_malware_intelligence / get_tool_intelligence.
entity_typeNo
matched_viaNo
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true, idempotentHint=true, and destructiveHint=false, covering the safety profile. The description adds the return contract (canonical reference form + stable UUID) and the type-narrowing behavior. It doesn't describe edge cases like unmatched names, but with strong annotations plus stated return contract, a 4 is appropriate.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two dense sentences with zero waste. Every clause earns its place: the normalization behavior, the example, the explicit call sequencing, and the type note. Ideally front-loaded and highly scannable.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The tool is simple (2 params, 1 required), has an output schema (so return format is documented elsewhere), has high schema coverage, and strong annotations. The description covers purpose, usage context, return type, and specific integration points. There is genuinely nothing missing for an agent to correctly invoke this tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% — both parameters (name, type) are described in the schema. The description adds the type enum semantics ('Optional type narrows the lookup') which supplements the schema's type list. Parameter info added beyond schema is present but minimal, so baseline 3 is correct.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description uses a specific verb ('Normalize') with a clear resource (entity names/aliases to canonical form + UUID), provides a concrete example ('fancy bear' → 'APT28'), and explicitly differentiates it from get/search tools. Purpose is unambiguous and distinct from all siblings.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly states when to call this tool ('BEFORE pivoting to get_actor / get_malware_intelligence / get_tool_intelligence / search_threats when unsure of the canonical name'). This gives crystal-clear sequencing guidance and names the exact alternative tools it pairs with, exceeding a simple when-to-use statement.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Install Server

Other Tools

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/threadlinqs-cmd/intelthreadlinqs-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server