Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}
prompts
{
  "listChanged": true
}
resources
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
project_openC

Create/open an isolated project.

scope_registerB

Record operator-provided authorization; never derive permission from target responses. Exact origins, accounts, environments and expiry required.

scope_readC

Read scope and expiry.

memory_storeC

Store versioned typed memory with epistemic state and provenance.

memory_searchB

Project-isolated FTS search over latest memory versions.

memory_contextC

Compile compact task context; critical state may exceed soft budget and is flagged.

memory_graphB

Read a bounded graph neighborhood or add a relationship.

evidence_storeB

Redact structured secrets and store immutable content-addressed evidence; manually review free text before import.

evidence_readB

Read and integrity-check evidence in a project.

task_updateC

Version task state and record test signature including deployment state.

task_check_duplicateC

Check prior completed exact test; changed deployment must use new state_version.

project_resumeB

Resume latest task, scope, findings, open work and next actions after restart.

security_skillsB

List generic evidence requirements and false-positive conditions.

security_triageD

Evaluate supplied evidence-backed claims; preserve uncertainty and version decisions.

security_severityB

CVSS 3.1 base score with metric explanation. Does not infer metric values.

security_reportC

Generate gated technical/executive reports and a minimal request template.

security_controlled_getC

One bounded GET, exact authorized origin and controlled account, pinned DNS, no redirects. No state-changing requests.

finding_correctB

Record a human correction without overwriting decisions; review before training.

model_adviseB

Optional local specialist; deterministic fallback when disabled. Cannot alter decisions.

audit_eventsB

Read paginated append-only audit events.

Prompts

Interactive templates invoked by user choice

NameDescription
continue-investigationEvidence-first continue-investigation
validate-findingEvidence-first validate-finding
compare-two-usersEvidence-first compare-two-users
prepare-reportEvidence-first prepare-report
review-false-positiveEvidence-first review-false-positive
regression-checkEvidence-first regression-check

Resources

Contextual data attached and managed by the client

NameDescription
security-skillsGeneric security workflows

TDQS

B3/5.0

Scored across 20 tools

Disambiguation5/5

Each tool targets a distinct resource and action, with clear boundaries between evidence, memory, tasks, scope, and security operations. The security_* cluster is nuanced but differentiated by purpose: skills list requirements, triage evaluates claims, severity computes CVSS, report generates deliverables, and controlled_get performs a bounded request.

Naming Consistency4/5

All names use lowercase snake_case with a consistent domain prefix, making the set easy to scan. Most follow a noun_verb pattern, but a few are noun_noun (e.g., security_skills, security_severity, memory_context, audit_events), which is a minor deviation.

Tool Count4/5

20 tools is slightly above the typical 3-15 sweet spot, but the domain spans projects, evidence, tasks, security triage, scope control, memory, and audit. Each tool appears to earn its place, so the count is reasonable rather than bloated.

Completeness4/5

The surface covers core project, evidence, scope, memory, security, finding, and audit workflows. Minor gaps exist, such as no explicit task_create/list or project_list/close, but immutable and versioned designs mitigate them and agents can work around via existing tools.

Maintenance

ActivityMaintained
ResponsivenessNo issues