Skip to main content
Glama

Raw HTB API Call

htb_raw

Call any Hack The Box API endpoint directly when a typed tool is missing or an endpoint moved; set method, path, JSON body, base URL, or save binary output.

Instructions

Escape hatch: call any HTB API endpoint directly. Hits the v4 base (https://labs.hackthebox.com/api/v4) by default — pass baseUrl 'https://labs.hackthebox.com/api/v5' for v5 endpoints. path like '/machine/active' (leading slash optional); data takes a raw JSON string body. Set output to save a binary response (for example, GET /challenge/download/) instead of decoding it as text. Relative output paths resolve under the toolkit directory. Use when a typed tool is missing or an endpoint moved.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
dataNoRaw JSON request body string
pathYesAPI path, e.g. '/machine/active'
methodYesHTTP method
outputNoSave the response body to this file path
baseUrlNoOverride API base URL (use the v5 URL for v5 endpoints)

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.1

TDQS

A4.5/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations only declare readOnlyHint=false and openWorldHint=true; the description adds real behavioral context beyond that — default v4 base URL, v5 override, leading-slash tolerance, raw JSON body format, binary-output saving, and relative-path resolution under the toolkit directory. It stops short of stating auth requirements or error/status handling for a tool that can issue DELETE/POST, which keeps it out of the top band.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads the escape-hatch purpose and the routing condition, then packs concrete usage details. It is dense and multi-clause, but each sentence carries actionable information; the baseUrl and output sentences in particular are not padding.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 5-parameter, untyped passthrough with no output schema, the description covers base URL selection, path/data formats, and binary-output behavior — enough to invoke it correctly. Remaining gaps (auth expectations, behavior on non-2xx responses) are real but secondary given the openWorld annotation.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% so the baseline is 3, but the description genuinely adds meaning: baseUrl is explained as the v5 override, data as a raw JSON string, output as a binary-save target with relative paths resolved under the toolkit directory, and path's optional leading slash. These are semantics not present in the schema text.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource ('call any HTB API endpoint directly') and frames itself as an 'escape hatch', which cleanly separates it from the typed siblings like htb_machine_list or htb_challenge_info. An agent can identify its role without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives an explicit routing rule: 'Use when a typed tool is missing or an endpoint moved.' That is precisely the when-to-use condition that distinguishes this fallback from the ~21 typed siblings, leaving nothing to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.