Comprehensive ServiceNow AI toolkit with 500+ MCP tools, including incident management, CMDB operations, ATF testing, scripting, Now Assist integration, and multi-module support. Works with Claude, ChatGPT, Gemini, Cursor, and other LLMs.
The NowAIKit server provides 19 tools with generally clear names following verb_noun conventions (search_tools, query_records, get_table_schema, create_record, update_record, delete_record). Descriptions are present for all tools and range from moderate to good detail. However, there are significant gaps: (1) Input schemas visible in the provided data show descriptions for parameters, but full JSON Schema type information cannot be verified from the code excerpt provided, only parameter names and descriptions are shown. (2) Output schemas are NOT documented, the evaluation data does not include return type schemas for any tool, forcing LLMs to infer result structure. (3) Error handling guidance is minimal, tools do not describe recovery paths or error classifications. (4) Some parameter names are ambiguous or lack type suffixes (e.g., 'query' appears in multiple tools but formats differ; 'limit' is numeric but min/max not specified in descriptions). (5) The dry_run pattern on destructive operations (create_record, update_record, delete_record) is good practice, but dry_run is not clearly described in what it returns, does it show the resolved payload, a diff, or just validation? (6) Tool descriptions average ~150 chars (within 10 - 1024 baseline), but several are vague about WHEN to use them vs alternatives (e.g., search_cmdb_ci vs get_cmdb_ci). (7) No evidence of permission scopes or security-gating declarations in tool definitions.
Get CMDB data quality metrics (completeness of server and network CI data)
Create a new record in any ServiceNow table (requires WRITE_ENABLED=true). Pass dry_run=true to preview the resolved payload without writing.
Delete a record from any ServiceNow table (requires WRITE_ENABLED=true). Pass dry_run=true to preview the record that would be deleted without deleting it.
Get complete information about a specific configuration item
Find assignment group details by name or sys_id
Retrieve complete details of a specific record by sys_id
Output schemas not documented for any of the 19 tools. LLMs cannot predict result structure, forcing inference and increasing errors.
Error handling guidance absent. Tools do not describe recovery paths, retryability, or actionable error messages. Dry-run outputs not precisely specified.
Inferred effective spec: 2025-06-18+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | 2025-06-18+ | v2 |
| 2026-03-09 | F | 44 | - | v1 |
Get the structure and field information for a ServiceNow table
Look up user details by email or username
Monitor critical infrastructure events
List discovery schedules and their run status
List MID servers and verify they are healthy
Show parent and child relationships for a CI
Search ServiceNow using plain English
Query ServiceNow records with filtering, field selection, pagination, and sorting
Search for configuration items (CIs) in the CMDB
Search the full NowAIKit tool catalog (400+ tools) by keyword to discover the right tool without loading every definition. Returns matching tool names + descriptions ranked by relevance. Use this FIRST when you are unsure which tool to call. Especially useful with MCP_TOOL_DISCOVERY=lean, which exposes only a small core set plus this search.
View service dependencies and related CIs for impact analysis
Update an existing record in any ServiceNow table (requires WRITE_ENABLED=true). Pass dry_run=true to preview a before→after field diff without writing.
Lint-check a ServiceNow encoded query BEFORE running it: validates javascript: expressions against the safe function allowlist, length limits, and common mistakes (e.g. using = instead of ^, raw spaces). Returns { valid, issues, suggestions }.
Parameter constraints underspecified. Numeric parameters (limit, page_size) lack min/max bounds. Enum constraints not declared where applicable. LLMs may pass invalid values.
Tool composition ambiguity. Unclear when to use get_record vs get_cmdb_ci, get_user alone vs search via query_records, or natural_language_search vs explicit query_records. LLM may select wrong tool.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint) visible in schema. Cannot differentiate safe vs risky operations at protocol level.
Descriptions too brief for discovery. Multiple tools (get_user, get_group, cmdb_health_dashboard) have descriptions under 50 chars, insufficient for LLM selection reasoning.
No permission scopes or security declarations. Tools do not state which permissions (read:incident, write:change, etc.) are required, limiting least-privilege configuration.
Parameter name ambiguity. 'query' parameter appears in multiple tools with different encoding formats (encoded query vs natural language). Parameter type suffixes missing (e.g., 'limit' should clarify numeric type).
STDIO-only transport. Server is not remotely accessible and cannot be used by hosted MCP clients. Protocol readiness capped at 50.