Get user is password set status
retrieveUserIsPasswordSetGet user is password set status - Get info about idm user if the password is set.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| userId | No | ||
| x-trace-id | No | ||
| x-request-id | Yes |
retrieveUserIsPasswordSetGet user is password set status - Get info about idm user if the password is set.
| Name | Required | Description | Default |
|---|---|---|---|
| userId | No | ||
| x-trace-id | No | ||
| x-request-id | Yes |
Changes observed during successful MCP inspections. Dates show when Glama detected each change.
Input schema / properties / x-hapi-auth-stateRemoved value: -{
- "type": "string"
-}Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true and destructiveHint=false, so the safety profile is known. The description adds minimal value beyond that, only restating the read operation. It does not describe response format, edge cases, or any permission requirements, but the annotations lower the bar for a simple read tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is very short but contains redundancy: 'Get user is password set status' and 'Get info about idm user if the password is set' convey the same fact. While it is front-loaded, the second half adds only the 'idm' context, which could be merged into a single, clearer sentence.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple read tool with no output schema, the description is too sparse. It fails to explain what 'password set' means, what the return value represents (e.g., boolean), or how to identify the user. Given the lack of parameter semantics and usage guidance, it is incomplete even for a low-complexity operation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, and the description does not explain any of the three parameters. Crucially, userId (the key functional input) is not mentioned in the description. Correlation IDs (x-request-id, x-trace-id) are also left unexplained, leaving the agent without the necessary semantics to correctly populate parameters.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool retrieves the password-set status for an IDM user, using a specific verb and resource. It is distinguishable from sibling tools like retrieveUser, which likely returns broader user info. The phrasing is awkward but the intent is unambiguous.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is provided on when to use this tool versus alternatives like retrieveUser or other user-related retrieval tools. There are no contextual cues, prerequisites, or exclusions, leaving the agent to infer usage from the name alone.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Add one secure layer between your agents and this server.
Many tools have clearly distinct CRUD roles per resource, but there are several confusing overlaps: start/stop/restart/shutdown/rescue are similar lifecycle actions, and there are duplicate audit tools like retrieveImageAuditsList and retrieveImageAuditsList1 (one even mislabeled as DNS Zones audit). Additionally, retrieveTagAuditsList appears to duplicate retrieveAssignmentsAuditsList, and updateDnsZoneRecord incorrectly says 'Create resource record'. These overlaps and mislabeled descriptions make it hard to pick the right tool.
The naming is a mix of camelCase verb_noun patterns, but inconsistent. Some tools use 'retrieveXList' while others use 'listX', some use 'Cancel' with a capital letter, and 'tool_search' uses snake_case. Numeric suffixes like 'retrieveImageAuditsList1' and verbs like 'patchInstance' instead of 'updateInstance' further break consistency.
With 124 tools, this is an extremely large tool surface for an MCP server. Even for a broad cloud provider API, this overwhelms an agent's context and selection capabilities. The number far exceeds reasonable scoping and creates unnecessary selection overhead.
The tool set covers a wide range of resources thoroughly: instances, snapshots, images, private networks, object storage, DNS, domains, tags, roles, users, secrets, and audits. Most resources have create/retrieve/update/delete lifecycle operations, and there are extensive audit history tools. Minor gaps exist (e.g., no explicit instance deletion besides cancel, no separate firewall management beyond upgradeInstance), but overall the surface is quite complete for its domain.