MCP server for AUXO Zero Trust and Ticket management platform, providing tools for managing protect surfaces, locations, states, contacts, assets, measures, readiness assessments, and ticket cases
This server provides 45 tools across 6 domains (Protect Surfaces, Locations, States, Contacts, Assets/Measures, Transactions, Readiness, Cases) with complete input schemas and consistent descriptions. Strengths: all tools have explicit parameter schemas with types and descriptions, clear verb-based naming (create/list/get/update/delete pattern), and risk classification. Weaknesses: descriptions are uniformly terse (60-80 chars average), lacking context about WHEN to use tools, dependencies, and error recovery. Output schemas are not documented in the provided code. Many tools lack guidance on pagination limits, valid value ranges, or error conditions. No evidence of dry-run/confirmation patterns for destructive operations. The server achieves mid-range quality, functional definitions with room for richer LLM guidance.
Add a note to a case
Create a case/ticket in the system
Create a new contact
Create a new location
Create a new protect surface
Create a protect surface measure relationship
Create and submit a readiness assessment with answers
Output schemas are not documented in source code. No visible documentation of what fields each tool returns, their types, or whether pagination is supported.
Descriptions are uniformly terse (50-80 chars) and lack actionable context. Do not answer: WHEN to use this tool vs. similar ones, what errors might occur, what the agent should do next on failure, or dependencies on other tools.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 70 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 49 | - | v1 |
Create a new state for a protect surface
Create a transaction flow between protect surfaces
De-escalate a case
Delete a contact
Delete a location
Delete a protect surface
Delete a protect surface measure
Delete a state
Delete a transaction flow
Escalate a case
Get a specific case by ID
Get full details of a contact by its ID
Get full details of a location by its ID
Get full details of a protect surface by its ID
Get a specific protect surface measure
Get a specific readiness assessment by ID
Get full details of a state by its ID
Get a specific transaction flow
List all assets
List all cases/tickets
List all contacts with optional filters
List all locations
List all available security measures from the AUXO catalog
List protect surface measures with optional filters
List Protect Surfaces, returning a lightweight summary (id, name, relevance) for each. All filter parameters are optional; with none supplied, every protect surface is returned. When multiple filters are supplied, all conditions must match (AND).
List all readiness assessments
List all states with optional filters
List all transaction flows between protect surfaces
Start a Zero Trust readiness assessment and return assessment questions
Update the primary contact of a case
Update the priority of a case
Update the subject of a case
Update a contact
Update a location
Update a protect surface
Update a protect surface measure
Update a state
Update a transaction flow
No evidence of error handling guidance. Descriptions do not tell LLMs what to do when a tool fails (e.g., 'User not found, try search_contacts() first'). This forces agents to guess recovery strategies.
No pagination parameters visible in list tools (listProtectSurfaces, listLocations, etc.). Without limit/offset or cursor, agents cannot handle result sets larger than memory/context.
Destructive tools (deleteProtectSurface, deleteLocation, deleteState, deleteContact, deleteProtectSurfaceMeasure, deleteTransactionFlow) lack confirmation or dry-run patterns. LLMs can accidentally delete data in a single failed reasoning step.
Tools accepting enum-like values (e.g., case_type with values 'securityincident, incident, change, standardchange, inforequest') lack enum constraints in schemas. LLMs can hallucinate invalid values.
Parameter descriptions lack format/constraint details. E.g., 'Priority 1-4' is mentioned in text but should be enforced in schema minimum/maximum. 'Confidentiality score (1-5)' and 'Maturity level (1-5)' lack validation ranges.
listAssets and listMeasures have empty input schemas with no filter parameters. Unclear what data these return or whether filtering is supported.
Multiple similar update tools (updateCasePriority, updateCasePrimaryContact, updateCaseSubject, escalateCase, deescalateCase) could be consolidated. Agents must reason about which granular tool to call, wasting tokens.