Skip to main content
Glama
AIWerk

@aiwerk/mcp-server-vault

by AIWerk

save_generated_secret

Store an agent-generated secret as an encrypted, create-only vault item, with automatic metadata and optional expiry. Prevents overwriting existing credentials by rejecting name collisions.

Instructions

Save an agent-generated secret into the mcp-agent-created collection. CREATE-only: cannot overwrite an existing item (name collision returns an error). The secret is E2E-encrypted with the vault org key before transmission. Sets mcp-created-by, mcp-created-at, mcp-expires-at, and mcp-used-in custom fields automatically. Blocked when READ_ONLY=1. Logs to DRY_RUN without creating a real cipher when DRY_RUN=1.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameYesUnique name for this secret within the mcp-agent-created collection. Case-sensitive. Name collision returns an error. Pick a distinct name.
typeYesLogical type of this secret. "password" for user passwords, "api-key" for API tokens and keys.
notesNoOptional non-sensitive annotation (e.g. where this key is used). Not the secret itself.
valueYesThe secret value to store (max 4096 chars). Assumed already generated by the agent.
used_inNoFree-form context string, e.g. "publish_protected_html @ aiwerk.ch/press/2026-05". Stored as mcp-used-in custom field.
expires_in_daysNoDays until the secret expires (sets mcp-expires-at). Default 30, max 365.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changedv0.2.3
    • changedInput schema / properties / name / description
      Previous value: -"Unique name for this secret within the mcp-agent-created collection. Case-sensitive. Name collision returns an error — pick a distinct name."New value: +"Unique name for this secret within the mcp-agent-created collection. Case-sensitive. Name collision returns an error. Pick a distinct name."
  2. First observedv0.2.2

TDQS

A4.2/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Goes well beyond the annotations, which only declare readOnlyHint=false and openWorldHint=true. The description discloses E2E encryption before transmission, auto-populated custom fields, blocking under READ_ONLY=1, and DRY_RUN logging behavior – rich operational context an agent cannot get from structured fields.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Dense but front-loaded: the core action leads, followed by the CREATE-only constraint and behavioral caveats. Each clause carries a distinct fact, though the run-on stream of constraints is slightly dense.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a write tool with full schema coverage and no output schema, the description covers creation semantics, overwrite behavior, encryption, auto-fields, and both READ_ONLY and DRY_RUN gating conditions. Nothing essential to correct invocation is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents all six parameters thoroughly. The description adds only minor mapping detail (mcp-expires-at, mcp-used-in custom fields) that overlaps with the schema, so the baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Specific verb+resource ('Save an agent-generated secret into the mcp-agent-created collection') with a clearly bounded scope. It distinguishes itself from the sibling save_login_item by specifying the agent-generated, mcp-created-collection target rather than a generic login item.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It states the CREATE-only constraint and that name collisions error, which is useful context for invocation. However, it never names when to use this over save_login_item or the other siblings, leaving the primary routing decision to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.