Official Infisical MCP Server for secrets management integration
The Infisical MCP server presents well-structured tool definitions with complete JSON schemas, clear descriptions, and proper use of enums for constrained inputs. All 10 tools are explicitly registered with schemas visible in src/index.ts. Tool names follow verb_noun conventions (create-secret, delete-secret, list-secrets, etc.). Descriptions are present and reasonably detailed (typically 40-90 characters), explaining the action and context. However, several patterns are underutilized: (1) No output schemas are documented, only input schemas are visible; (2) Parameter descriptions lack constraint guidance (e.g., no mention of format, length, or allowed patterns beyond enums); (3) Error handling is not visible in the tool definitions; (4) No idempotency hints or permission declarations; (5) Secrets are passed as parameters rather than injected server-side (HIGH RISK). The code shows solid engineering (Zod validation, environment-based auth injection, masking support), but the tool interface itself has gaps typical of mid-tier production servers.
Create a new environment in a project
Create a new folder/path in an environment
Create a new project in Infisical
Create a new secret in Infisical
Delete a secret in Infisical
Get a specific secret by name
Invite members to a project
No output schemas documented. Tool definitions show input schemas only; LLMs cannot infer what fields are returned or plan downstream tool calls.
secretValue parameter passed as tool input exposes secrets in agent traces and logs. Should use environment variable injection (INFISICAL_TOKEN) pattern instead. Credentials must never appear as tool parameters.
Parameter descriptions lack constraint details. E.g., 'The ID of the project' does not explain format, length, or character restrictions.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 67 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
List all projects
List all secrets in a specific environment
Update a secret in Infisical
Destructive operations (delete-secret) lack confirmation/dry-run support. No evidence of confirmation-request pattern to prevent accidental deletions by agents.
list-secrets and list-projects do not document pagination support. No evidence of limit/offset or cursor parameters, nor a total_count return field. Large result sets could exceed context window.
No permission declarations (read:secrets, write:secrets, etc.) visible in tool definitions. Tools should declare required scopes for least-privilege agent configuration.
Error handling guidance not visible in tool definitions. No evidence of recovery guides or error categorization (retryable vs user-fixable vs fatal).