Skip to main content
Glama

trooth_outside_in_read

Read-onlyIdempotent

Perform a live, neutral read of a domain's public security surface right now: HTTPS/TLS reachability, common security headers (HSTS, CSP, nosniff, frame protection, referrer policy), and /.well-known/security.txt. These are observations from the public internet, not witnessed evidence and not a grade.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
domainYesDomain to read, e.g. example.com

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
statusYesMachine-branchable outcome for this lookup.
subjectYesThe company, domain or token this answer is about.
summaryYesThe same answer as the text content, for display.
claim_urlNoPresent only when the subject has no published record and could be claimed by its owner.
provenanceYesWhere this answer came from. An honest_absence is missing data, never a judgment about the subject.

Schema Changelog

Changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. Changed1 schema field changed
    • changedOutput schema / (root)
      Previous value: -nullNew value: +{
      +  "properties": {
      +    "claim_url": {
      +      "description": "Present only when the subject has no published record and could be claimed by its owner.",
      +      "type": "string"
      +    },
      +    "provenance": {
      +      "description": "Where this answer came from. An honest_absence is missing data, never a judgment about the subject.",
      +      "enum": [
      +        "witnessed_signed",
      +        "signed_scan",
      +        "live_observation",
      +        "honest_absence",
      +        "withheld_by_owner",
      +        "knowledge_base",
      +        "input_error"
      +      ],
      +      "type": "string"
      +    },
      +    "status": {
      +      "description": "Machine-branchable outcome for this lookup.",
      +      "enum": [
      +        "published",
      +        "listed",
      +        "unclaimed",
      +        "private",
      +        "observed",
      +        "valid",
      +        "invalid",
      +        "expired",
      +        "revoked",
      +        "answered",
      +        "out_of_scope",
      +        "bad_input"
      +      ],
      +      "type": "string"
      +    },
      +    "subject": {
      +      "description": "The company, domain or token this answer is about.",
      +      "type": "string"
      +    },
      +    "summary": {
      +      "description": "The same answer as the text content, for display.",
      +      "type": "string"
      +    }
      +  },
      +  "required": [
      +    "status",
      +    "provenance",
      +    "subject",
      +    "summary"
      +  ],
      +  "type": "object"
      +}
  2. First observed

TDQS

A4.3/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint, openWorldHint, idempotentHint, and destructiveHint. The description adds behavioral context beyond that: results are time-sensitive ('right now'), are observations from the public internet, and are explicitly not witnessed evidence or a grade. This clarifies the epistemic status and limitations of the returned data, with no contradiction to annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences with no filler. The first sentence front-loads the action, target, and the exact checks performed; the second concisely clarifies the nature of the output. Every clause earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a single-parameter read-only tool with rich annotations and an output schema present, the description is complete. It explains what is observed, the live/neutral nature, and what the results are not. There is no missing information an agent needs to decide whether to invoke this tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The only parameter, domain, has a clear schema description ('Domain to read, e.g. example.com') with 100% coverage. The tool description does not add any additional semantic details about the parameter beyond what the schema already provides, so the baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb and resource ('Perform a live, neutral read of a domain's public security surface') and enumerates exactly what is checked (HTTPS/TLS, security headers, security.txt). It also differentiates itself from similar tools by explicitly noting it is 'not witnessed evidence and not a grade', which separates it from trooth_verify and trooth_public_trust_profile without needing to open schemas.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives clear context for when to use it: a 'live, neutral read right now' of the public security surface. It implicitly excludes other use cases with 'not witnessed evidence and not a grade', but it does not explicitly name sibling tools or provide direct when-to-use vs alternative guidance, so it falls shy of a 5.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A4.4/5.0
Disambiguation5/5

Each tool targets a distinct purpose: product Q&A, live security observation, published trust profile lookup, and token verification. Even the two domain-related tools are clearly separated by live scan versus published record.

Naming Consistency3/5

All tools share the trooth_ prefix and snake_case style, but the post-prefix names are mixed: ask and verify are bare verbs, outside_in_read is a compound verb, and public_trust_profile is a noun. This is readable but not a consistent verb_noun pattern.

Tool Count5/5

Four tools is a well-scoped count for this server's purpose. Each tool earns its place with no obvious redundancy or bloat.

Completeness5/5

The tool surface covers the core read-only lifecycle: product knowledge, live security reads, trust profile lookup, and token verification. There are no obvious dead ends or missing operations for the apparent domain.

Resources