Skip to main content
Glama

Attack Summary

attack_summary
Read-onlyIdempotent

Layer-7 DDoS attack mix over a time window. Returns the percentage breakdown of attacks by mitigation product or attack vector. Filter by location to scope to a region/country.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
locationNo2-letter location code (optional)
dimensionNoSummary dimension: mitigation_product | http_method | http_version | ip_version | bot_class (default mitigation_product)
date_rangeNoLookback window (default 28d)

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
locationYesLocation code or GLOBAL
dimensionYesSummary dimension (mitigation_product, http_method, etc.)
date_rangeYesLookback window applied
breakdown_pctYesPercentage breakdown by dimension

Schema Changelog

Changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. Changed2 schema fields changed
    • addedInput schema / examples
      Added value: +[
      +  {
      +    "dimension": "mitigation_product",
      +    "location": "DE"
      +  },
      +  {
      +    "date_range": "7d",
      +    "dimension": "http_method"
      +  }
      +]
    • changedOutput schema / (root)
      Previous value: -nullNew value: +{
      +  "properties": {
      +    "breakdown_pct": {
      +      "additionalProperties": {
      +        "type": "number"
      +      },
      +      "description": "Percentage breakdown by dimension",
      +      "type": "object"
      +    },
      +    "date_range": {
      +      "description": "Lookback window applied",
      +      "type": "string"
      +    },
      +    "dimension": {
      +      "description": "Summary dimension (mitigation_product, http_method, etc.)",
      +      "type": "string"
      +    },
      +    "location": {
      +      "description": "Location code or GLOBAL",
      +      "type": "string"
      +    }
      +  },
      +  "required": [
      +    "dimension",
      +    "location",
      +    "date_range",
      +    "breakdown_pct"
      +  ],
      +  "type": "object"
      +}
  2. First observed

TDQS

B3.4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint, idempotentHint, etc. The description adds that the tool returns a percentage breakdown over a time window, which is useful context. However, it does not disclose any additional behavioral details beyond what annotations provide.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two sentences, front-loaded with the core purpose, and contains no redundant or vague language. Every sentence adds value.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the presence of an output schema and annotations, the description explains the tool's purpose and filtering capability adequately. It could mention defaults, but the schema covers that. Overall complete for the tool's complexity.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so baseline is 3. The description mentions 'location' and 'dimension' (mitigation product or attack vector), but the schema already describes each parameter equivalently. The description adds minimal new meaning.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool returns a 'percentage breakdown of attacks by mitigation product or attack vector' over a time window, specifying it's for 'Layer-7 DDoS attacks'. It is specific about the resource and action, but does not explicitly distinguish from sibling tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description indicates when to use the location filter but provides no guidance on when to choose this tool over alternatives. Given many sibling tools, this omission limits the agent's ability to correctly select it.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A3.6/5.0
Disambiguation2/5

There are three ask_pipeworx variants that overlap heavily, plus five polymarket_* tools scanning similar market edges, and meta-tools like discover_tools, suggest_questions, and deep_research that blur together. ai_visibility_check and scan_competitor_ai_presence also overlap. The Cloudflare Radar tools are distinct, but they are a small minority in a sea of overlapping data/prediction-market tools.

Naming Consistency3/5

Most tools use snake_case, but the pattern is inconsistent: some are verb_noun (list_subscriptions, resolve_entity, scan_dependency), some are noun_phrase (bgp_leaks, internet_quality, radar_domain_rank), and some use vendor-prefixed naming inconsistently (ask_pipeworx vs pipeworx_feedback vs pipeworx_trending). It is readable but not predictable.

Tool Count2/5

37 tools is heavy for any single server, and the collection spans unrelated domains: Cloudflare Radar, Pipeworx data lookup, Polymarket betting, memory, subscriptions, and npm scanning. The count feels like a bundled platform rather than a focused tool set, and many tools could be split into separate servers.

Completeness3/5

The Pipeworx data-research side is quite complete (ask, grounded, deep_research, entity_profile, compare_entities, validate_claim, resolve_entity, discover_tools, recent_changes), and the prediction-market side has good coverage (edges, arbitrage, fill risk, cross-venue spread, tracking). However, the Cloudflare Radar portion is thin—only six tools cover a service known for many more traffic/attack/outage metrics—and the overall surface has no cohesive domain to judge completeness against.