MCP server for interacting with IT Glue API, providing tools for documentation management, asset tracking, and password management
The IT Glue MCP server defines 16 tools with generally good naming conventions (all use action-verb prefixes like search_, get_, create_, update_, delete_, list_). All tools have descriptions present in the schema. However, there are critical gaps: (1) Input schemas are defined in the code but parameter-level descriptions are minimal or missing for many parameters, particularly filter objects which are typed as generic 'object' with no property definitions. (2) Output schemas are not documented anywhere in the visible source code, critical for LLM planning. (3) Risk annotations (READ_ONLY, WRITE, DESTRUCTIVE) are present in metadata but not formally registered as MCP toolAnnotations in the visible schema definitions. (4) Error handling lacks recovery guidance; no examples of structured error responses. (5) The 'filter' parameter pattern (appearing in search_organizations, search_documents, search_configurations, search_passwords, search_flexible_assets) is underspecified, no description of what filters are valid or how to use them. (6) Pagination is mentioned for user_metrics but not consistently applied or documented across all list/search tools. Example: search_organizations accepts a 'filter' object but provides zero documentation of what keys that object should contain or what values are valid.
Create a new document in IT Glue
⚠ DESTRUCTIVE: Delete a document from IT Glue
Retrieve details for a specific configuration (device/asset) from IT Glue
Retrieve a specific document from IT Glue with full content and metadata
Retrieve details for a specific flexible asset from IT Glue
Retrieve details for a specific organization from IT Glue
Retrieve password details from IT Glue (value is intentionally redacted in output)
Generic 'filter' parameters lack property-level documentation. Multiple tools (search_organizations, search_documents, search_configurations, search_passwords, search_flexible_assets) accept a 'filter' object typed as generic 'object' with no schema definition of valid keys, value types, or usage examples. LLMs cannot determine what filters are available without trial and error.
Output schemas not documented. The source code shows tool definitions and descriptions but does not include formal output schema documentation. LLMs need to know what fields each tool returns to plan downstream calls and extract relevant data for chaining.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 71 | 2026-07-28+ | v2 |
List document folders for an organization in IT Glue
List user activity metrics from IT Glue for a date range
Search for configurations (devices/assets) in IT Glue
Search for documents in IT Glue by name, organization, or other criteria
Search for flexible assets in IT Glue
Search for organizations in IT Glue by name or other criteria
Search for password entries in IT Glue
Update an existing document in IT Glue
Upload an attachment to an IT Glue resource (document, configuration, etc.)
Risk annotations (READ_ONLY, WRITE, DESTRUCTIVE) present in metadata but not formally registered as MCP tool annotations. The rubric requires toolAnnotations=true and proper use of readOnlyHint, destructiveHint, and idempotentHint fields in the MCP schema. Current implementation appears to tag these in the summary but not in the formal MCP tool definition.
Error handling lacks recovery guidance. No visible error response schemas or recovery hints. Errors should tell the LLM what to do next (e.g., 'Try search_organizations() if you only have a partial name'). Current implementation likely returns raw API errors without guidance.
Pagination inconsistency. list_user_metrics documents date-range filtering and sorting, but other search/list tools (search_documents, search_configurations, search_passwords, search_flexible_assets) do not document pagination parameters (limit, offset, page, cursor). Large result sets will blow context windows without clear pagination guidance.
Missing natural-identifier fallbacks. Tools like get_organization, get_document, get_configuration require opaque IDs. No variants accepting human-friendly names (e.g., 'organization name' instead of 'organizationId'). Users must do extra lookup steps.