List secrets
retrieveSecretListList secrets - List and filter all secrets in your account.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | No | ||
| page | No | ||
| size | No | ||
| type | No | ||
| orderBy | No | ||
| x-trace-id | No | ||
| x-request-id | Yes |
retrieveSecretListList secrets - List and filter all secrets in your account.
| Name | Required | Description | Default |
|---|---|---|---|
| name | No | ||
| page | No | ||
| size | No | ||
| type | No | ||
| orderBy | No | ||
| x-trace-id | No | ||
| x-request-id | Yes |
Changes observed during successful MCP inspections. Dates show when Glama detected each change.
Input schema / properties / x-hapi-auth-stateRemoved value: -{
- "type": "string"
-}Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true and destructiveHint=false, covering the safety profile. The description adds the scope of operation ('account-wide') and filter capability, but does not disclose pagination, ordering, or response format behavior, which is acceptable given annotation coverage.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is brief but redundant: 'List secrets - List and filter...' repeats the tool name and title unnecessarily. It could be more concise with a single clause, wasting a few words without adding substance.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With 7 parameters, no output schema, and no parameter documentation, the description is severely under-specified. It fails to clarify required request ID, filtering options, pagination, or return structure. Even with annotations covering safety, this is inadequate for a tool of this complexity.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, so the description must compensate. It only mentions 'filter' generically without specifying any parameter names (e.g., name, type, page, size) or their semantics. This adds minimal value for understanding the 7 parameters.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool lists and filters all secrets in the account, using a specific verb and resource. It distinguishes from sibling 'retrieveSecret' (singular) and other secret management tools like createSecret/deleteSecret/updateSecret.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The phrase 'List and filter all secrets in your account' implies the tool is intended for listing/querying secrets, providing clear context. It does not explicitly mention alternatives or exclusions, but the scope ('in your account') and contrast with sibling retrieveSecret make usage apparent.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Add one secure layer between your agents and this server.
Many tools have clearly distinct CRUD roles per resource, but there are several confusing overlaps: start/stop/restart/shutdown/rescue are similar lifecycle actions, and there are duplicate audit tools like retrieveImageAuditsList and retrieveImageAuditsList1 (one even mislabeled as DNS Zones audit). Additionally, retrieveTagAuditsList appears to duplicate retrieveAssignmentsAuditsList, and updateDnsZoneRecord incorrectly says 'Create resource record'. These overlaps and mislabeled descriptions make it hard to pick the right tool.
The naming is a mix of camelCase verb_noun patterns, but inconsistent. Some tools use 'retrieveXList' while others use 'listX', some use 'Cancel' with a capital letter, and 'tool_search' uses snake_case. Numeric suffixes like 'retrieveImageAuditsList1' and verbs like 'patchInstance' instead of 'updateInstance' further break consistency.
With 124 tools, this is an extremely large tool surface for an MCP server. Even for a broad cloud provider API, this overwhelms an agent's context and selection capabilities. The number far exceeds reasonable scoping and creates unnecessary selection overhead.
The tool set covers a wide range of resources thoroughly: instances, snapshots, images, private networks, object storage, DNS, domains, tags, roles, users, secrets, and audits. Most resources have create/retrieve/update/delete lifecycle operations, and there are extensive audit history tools. Minor gaps exist (e.g., no explicit instance deletion besides cancel, no separate firewall management beyond upgradeInstance), but overall the surface is quite complete for its domain.