MCP server for interacting with SiteMinder policy objects via FastMCP. Provides tools to list, search, and manage SiteMinder objects with support for OIDC, JWT, and static token authentication.
This server presents 40 tools across 8 SiteMinder object types (SmAgentConfig, SmAgent, SmPolicyDomain, SmRule, SmResponse, SmUser, SmGroup, SmRealm, SmResource, SmPolicy). Each type has 5 tools: list_*_summary, search_*, get_*_detail, create_*. While the tool names follow a clear verb_noun pattern and descriptions are present, critical deficiencies emerge: (1) Input schemas for all 40 tools lack type constraints and enums. The 'detail' parameter for all create_* tools is typed as 'string|object' with minimal guidance, LLMs cannot infer what fields are required or valid. (2) Output schemas are completely undocumented, no indication of what fields list_*, search_*, or get_detail_* return. (3) Parameter descriptions are minimal and generic. The 'filter_expression' param for all search tools shows the same boilerplate examples (Name contains 'login', Desc != null, IsEnabled = true, Level > 500) repeated across all 8 object types without object-specific guidance. (4) The create_* tools provide no schema for the 'detail' object, no required fields, no valid attributes, forcing agents to guess or hallucinate field names. (5) No error handling guidance (e.g., what happens if filter syntax is invalid, or required fields are missing from create detail). (6) The server does implement proper naming conventions (list_, search_, get_, create_) and descriptions exist for all tools, which prevents a lower score, but the lack of actionable input/output schemas and parameter specificity is a major gap in production readiness.
Create a new SmAgent object with the provided details.
Create a new SmAgentConfig object with the provided details.
Create a new SmGroup object with the provided details.
Create a new SmPolicy object with the provided details.
Create a new SmPolicyDomain object with the provided details.
Create a new SmRealm object with the provided details.
Create a new SmResource object with the provided details.
All 40 tools lack output schema documentation. list_*, search_*, and get_detail_* tools do not declare what fields are returned (e.g., does list_smagentconfig_summary return [name, id, status] or [name, id, status, description, enabled, type]?). Without output schemas, LLMs cannot extract chaining IDs for downstream calls or plan multi-step workflows.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 0 | - | v1 |
Create a new SmResponse object with the provided details.
Create a new SmRule object with the provided details.
Create a new SmUser object with the provided details.
Get detailed information about a specific SmAgent object by its ID.
Get detailed information about a specific SmAgentConfig object by its ID.
Get detailed information about a specific SmGroup object by its ID.
Get detailed information about a specific SmPolicy object by its ID.
Get detailed information about a specific SmPolicyDomain object by its ID.
Get detailed information about a specific SmRealm object by its ID.
Get detailed information about a specific SmResource object by its ID.
Get detailed information about a specific SmResponse object by its ID.
Get detailed information about a specific SmRule object by its ID.
Get detailed information about a specific SmUser object by its ID.
Show a summary of all SiteMinder SmAgent objects.
Show a summary of all SiteMinder SmAgentConfig objects.
Show a summary of all SiteMinder SmGroup objects.
Show a summary of all SiteMinder SmPolicy objects.
Show a summary of all SiteMinder SmPolicyDomain objects.
Show a summary of all SiteMinder SmRealm objects.
Show a summary of all SiteMinder SmResource objects.
Show a summary of all SiteMinder SmResponse objects.
Show a summary of all SiteMinder SmRule objects.
Show a summary of all SiteMinder SmUser objects.
Search SiteMinder SmAgent objects using a filter expression. Supported attributes: - Name - Description - IsEnabled - Type Examples: - Name contains 'login' - Desc != null - IsEnabled = true - Level > 500
Search SiteMinder SmAgentConfig objects using a filter expression. Supported attributes: - Name - Description - IsEnabled - Type Examples: - Name contains 'login' - Desc != null - IsEnabled = true - Level > 500 Examples: - Name contains 'aco_test' - Desc contains 'test'
Search SiteMinder SmGroup objects using a filter expression. Supported attributes: - Name - Description - IsEnabled - Type Examples: - Name contains 'login' - Desc != null - IsEnabled = true - Level > 500
Search SiteMinder SmPolicy objects using a filter expression. Supported attributes: - Name - Description - IsEnabled - Type Examples: - Name contains 'login' - Desc != null - IsEnabled = true - Level > 500
Search SiteMinder SmPolicyDomain objects using a filter expression. Supported attributes: - Name - Description - IsEnabled - Type Examples: - Name contains 'login' - Desc != null - IsEnabled = true - Level > 500
Search SiteMinder SmRealm objects using a filter expression. Supported attributes: - Name - Description - IsEnabled - Type Examples: - Name contains 'login' - Desc != null - IsEnabled = true - Level > 500
Search SiteMinder SmResource objects using a filter expression. Supported attributes: - Name - Description - IsEnabled - Type Examples: - Name contains 'login' - Desc != null - IsEnabled = true - Level > 500
Search SiteMinder SmResponse objects using a filter expression. Supported attributes: - Name - Description - IsEnabled - Type Examples: - Name contains 'login' - Desc != null - IsEnabled = true - Level > 500
Search SiteMinder SmRule objects using a filter expression. Supported attributes: - Name - Description - IsEnabled - Type Examples: - Name contains 'login' - Desc != null - IsEnabled = true - Level > 500
Search SiteMinder SmUser objects using a filter expression. Supported attributes: - Name - Description - IsEnabled - Type Examples: - Name contains 'login' - Desc != null - IsEnabled = true - Level > 500
All 8 create_* tools have dangerously vague input schemas. The 'detail' parameter accepts 'string|object' with only the description 'Object details as a dict or JSON string'. No indication of required fields, valid attributes, data types, or constraints. LLMs will hallucinate field names (e.g., passing 'Name' vs 'name' vs 'ObjectName') leading to validation failures or silent data misuse.
The 'filter_expression' parameter for all 8 search_* tools is under-specified. While examples are provided (Name contains 'login', Desc != null), the syntax grammar is not formally defined. What operators are supported (contains, =, !=, >, <, >=, <=, AND, OR)? What happens on invalid syntax? LLMs will guess and produce unparseable expressions, leading to silent failures or empty results.
No pagination support visible in list_* or search_* tools. If a SiteMinder policy domain contains 500+ objects, does list_smpolicydomain_summary return all 500? If so, the response will exhaust context windows. The code shows caching of 'top 3' details in fetch_and_cache_details(), but no limit or offset parameters are visible in the tool signatures.
No error handling guidance documented. If a search_* tool receives an invalid filter_expression, what error is returned? If create_* is called with missing required fields, does it return a 400 with field names or a generic 500? LLMs cannot recover from errors without clear, actionable error messages.
Tool descriptions are generic and repetitive. Example: 'Get detailed information about a specific SmAgent object by its ID.' is identical across all 8 get_*_detail tools. Descriptions do not distinguish when to call get_smagentconfig_detail vs get_smagent_detail, or what fields are returned. LLMs cannot use these descriptions to disambiguate or plan tool chains.