Streamlit-based orchestration platform for AV/IT operations with MCP tool integration, fixed agents (Baseline, Intake, Plan, Act, Verify, Learn), recipe management, and ServiceNow KB publishing. Supports SOP compilation, MCP tool scaffolding, and workflow automation with RBAC and maintenance windows.
The server exposes a single tool, KBPublisher, with a WRITE risk profile. While the tool has a basic description and visible input schema, the implementation lacks critical production-grade patterns: no output schema documentation, no error handling guidance, no parameter validation constraints, and the schema is inferred from source rather than formally registered. The description is adequate but generic (117 chars), and parameter descriptions are minimal to absent. No evidence of idempotency, dry-run, or confirmation patterns for this destructive operation. The server does not follow verb_noun naming ('KBPublisher' is a noun-focused class name, not an action verb like 'create_kb_article' or 'publish_kb_article'). Parameter 'meta' is vaguely typed as 'object' with no constraints. No evidence of rate limiting, permission gating, or audit trail support. The codebase shows Streamlit-based token resolution and health-check infrastructure, but no actual tool registration endpoint or MCP manifest visible.
Creates or updates ServiceNow KB articles from inputs (title, html body, tags, audience, metadata). Supports create and update operations with Bearer token or basic authentication.
Tool name 'KBPublisher' is a noun, not an action verb. Should be 'create_kb_article' or 'publish_kb_article' to clearly signal intent to the LLM.
No output schema documented. LLMs cannot know what fields (e.g., article_id, url, status) to expect from KBPublisher, preventing downstream tool chaining and forcing agents to infer structure.
Destructive operation (write to ServiceNow KB) lacks dry-run, confirmation, or idempotency pattern. No guidance on retryability or side effects if the call is duplicated.
Parameter 'meta' is typed as bare 'object' with no constraints, enums, or format guidance. This invites hallucinated or invalid metadata fields.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 41 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 23 | - | v1 |
Parameter 'audience' has a vague description ('Target audience for the KB article (default: All)'). No enum of valid audience values provided, leaving the LLM to guess allowed options.
No error handling guidance. If ServiceNow authentication fails, API quota exceeded, or HTML is malformed, the agent receives no actionable recovery path (e.g., 'Retry authentication', 'Wait 60s', or 'Validate HTML').
No evidence of permission checking. Any agent with access to KBPublisher can modify ServiceNow KB articles without role or scope verification.
Tool definition appears inferred from source code (kb_publisher.py) rather than explicitly registered in an MCP manifest or tool registry. No visible MCP server entrypoint or tool registration endpoint.