MCP server for Netskope's Zero Trust Network Access Platform management through LLM's
The server exposes 52 tools with inconsistent quality. Many tools have descriptions, but a significant portion have severely incomplete input schemas with empty properties objects (tools 2, 4, 9, 10, 12, 17, 18, 19, 20, 28, 41, 42, 43, 46, 50). This pattern indicates missing parameter definitions. Tool naming is generally verb-first and clear (getAlertConfig, createLocalBroker, etc.), which is positive. However, descriptions vary widely in quality, many are generic one-liners under 30 characters (e.g., 'Get alert configuration', 'Create a new local broker'). No output schemas are documented in any tool definition. Parameter descriptions are sparse; most parameters lack any guidance on expected format, range, or constraints. Error handling and recovery guidance are entirely absent from tool definitions. The server follows a consistent naming convention (verb_noun via camelCase), which helps LLM parsing, but the shallow definitions and missing schemas create high risk of misuse.
Add a publisher association for steering
Assign multiple publishers to an upgrade profile
Create a new local broker
Create local broker configuration
Create a new policy group
Create a new NPA policy rule
Create a new private application
Widespread missing input parameter schemas: 16 tools have empty properties objects (type: object, properties: {}), providing no guidance on required parameters, parameter names, types, or descriptions. Examples: updateAlertConfig, createLocalBroker, createPolicyRule, createPolicyGroup, etc.
Minimal tool descriptions: 30+ tools have descriptions under 30 characters (e.g., 'Get alert configuration', 'Update alert configuration', 'Create a new local broker'). These descriptions provide no context on when to use the tool, what it returns, or when it should be called vs. a similar tool.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 50 | - | v1 |
Create a new publisher
Create a new upgrade profile
Delete a local broker
Delete a policy group
Delete a policy rule
Delete a private application
Delete a publisher
Delete a publisher association
Delete an upgrade profile
Generate a registration token for a local broker
Generate a registration token for a publisher
Get admin users with pagination
Get alert configuration
Get a specific local broker by ID
Get local broker configuration
Get a specific policy group
Get a specific policy rule by ID
Get a specific private application
Get private apps associated with a publisher
Get a specific publisher by ID
Get available publisher releases
Get a specific upgrade profile by ID
Immediately upgrade multiple publishers without using upgrade profiles. For assigning publishers to upgrade profiles, use assignPublishersToProfile instead.
List SCIM groups with optional filtering and pagination
List local brokers with optional field filtering
List policy groups
List NPA policy rules with optional filtering and sorting
List private applications with filtering and search options
List publishers with optional field filtering
List all upgrade profiles
List SCIM users with optional filtering and pagination
Replace an existing publisher with full replacement
Search SCIM groups by various criteria
Search SCIM users by various criteria
Update alert configuration
Update an existing local broker
Update local broker configuration
Update an existing policy group
Update an existing private application
Update an existing publisher with partial updates
Update an existing publisher association
Update an existing upgrade profile
Update the schedule for an upgrade profile
Validate a resource name
Validate a resource
No documented output schemas: None of the 52 tools document what fields or structure will be returned. LLMs cannot plan downstream tool calls or extract the right data without knowing expected response fields (e.g., does listPrivateApps return app_id or id? What does createPrivateApp return?).
Missing parameter descriptions for critical parameters: Many parameters with names like 'id', 'type', 'resourceType', 'name' lack descriptions explaining their expected format, range, or constraints. Example: validateName has parameters 'resourceType' and 'name' with descriptions, but no guidance on valid values for resourceType.
No error handling or recovery guidance: Tool definitions contain no information about error conditions, error messages, or what the LLM should do if a call fails. This violates the recovery-guide pattern and forces agents to guess at retry logic.
No confirmation or dry-run for destructive operations: 11 tools marked DESTRUCTIVE (deleteLocalBroker, deletePolicyRule, deletePrivateApp, deletePublisher, deletePolicyGroup, deletePublisherAssociation, deleteUpgradeProfile) have no mention of confirmation steps or dry-run modes. Agents can accidentally destroy resources.