Skip to main content
Glama
MukundaKatta

password-mcp

by MukundaKatta

password-mcp

npm mcp license

MCP server: generate strong passwords and score password strength with zxcvbn. Randomness comes from Node's crypto.randomBytes with rejection sampling so the distribution is uniform across the chosen alphabet.

Tools

generate

{ "length": 20, "exclude_ambiguous": true }

{ "password": "aB3xK7nQ2wP9vR4zM8tL" }

Field

Default

Notes

length

20

4-256

lowercase

true

uppercase

true

digits

true

symbols

true

exclude_ambiguous

false

Drops 0 O 1 l I | etc.

At least one character from each enabled class is guaranteed.

strength

{ "password": "correct horse battery staple" }

{
  "score": 4,
  "guesses_log10": 17.34,
  "crack_time_display": "centuries",
  "warning": "",
  "suggestions": []
}

score is the zxcvbn 0-4 strength rating. guesses_log10 is the base-10 log of the estimated guesses needed.

Related MCP server: MCP Password Generator

Configure

{ "mcpServers": { "password": { "command": "npx", "args": ["-y", "@mukundakatta/password-mcp"] } } }

License

MIT.

Available Tools

2 tools
generateA

Generate a cryptographically random password. Enable lowercase/uppercase/digits/symbols (defaults: all on). Length 4-256.

ParametersJSON Schema
NameRequiredDescriptionDefault
lengthNo
lowercaseNo
uppercaseNo
digitsNo
symbolsNo
exclude_ambiguousNoDrop 0/O/1/l/I/| etc.

TDQS

A3.6/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description bears full responsibility. It states 'cryptographically random,' which is a key behavioral trait, but does not disclose other aspects like performance, permissions, or handling of invalid parameter combinations (e.g., all flags false).

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two concise sentences that are front-loaded: the first states the core purpose, the second adds essential details. No unnecessary words.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given 6 parameters and no output schema, the description lacks information on return format (the generated password as a string). It also does not explain edge cases like conflicting flags or how exclude_ambiguous works beyond the schema's brief description.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is only 17% (only exclude_ambiguous has a description). The description adds value by explaining that the boolean flags enable character types and defaults are all on, and length range 4-256. However, it does not detail each parameter beyond what is obvious from property names.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool generates a cryptographically random password. It specifies the character types (lowercase, uppercase, digits, symbols) and length range (4-256), making the purpose unambiguous. It distinguishes from the sibling 'strength' by focusing on generation rather than analysis.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage (generating passwords) but provides no explicit guidance on when to use this tool versus the sibling 'strength' or when not to use it. No alternatives or exclusions are mentioned.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

strengthA

Score a password with zxcvbn. Returns score 0-4, guesses_log10, human crack-time, and feedback.

ParametersJSON Schema
NameRequiredDescriptionDefault
passwordYes

TDQS

A3.9/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description must disclose behavior. It states that the tool scores a password and returns specific metrics, implying a read-only operation with no side effects. However, it could explicitly confirm no mutation.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single concise sentence that front-loads the primary action and lists return values. Every word is necessary and efficient.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a simple tool with one parameter and no output schema, the description adequately covers the return fields (score, guesses_log10, etc.). However, it does not detail the structure of the feedback object, which could be helpful.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must add value. It mentions 'password' as the input but does not elaborate on format, constraints, or other requirements beyond what the schema indicates. Minimal additional context.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool scores a password with the zxcvbn algorithm and lists the return values (score 0-4, guesses_log10, human crack-time, feedback). It distinguishes itself from the sibling tool 'generate' which likely creates passwords.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage for password strength checking but provides no explicit guidance on when to use this tool versus alternatives, nor does it mention any preconditions or limitations.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

TDQS

A3.9/5.0
Disambiguation5/5

The two tools have completely distinct purposes: one generates passwords, the other evaluates their strength. There is no overlap or ambiguity.

Naming Consistency4/5

The names are simple and clear, but one is a verb ('generate') and the other is a noun ('strength'), which is a minor inconsistency. A more consistent pattern would be 'generatePassword' and 'checkStrength'.

Tool Count5/5

Two tools is appropriate for a focused password utility: generation and strength assessment. No extraneous tools, and the scope is well-defined.

Completeness4/5

The tool set covers the core password operations: generation and strength evaluation. It is missing features like hashing or breach checking, but the scope is reasonable for a minimal MCP server.

Maintenance

ActivityStale
ResponsivenessSyncing

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    Provides random number generation utilities, including a secure UUID generator powered by Node's crypto module.
    7
    21
    3
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    Generates secure random passwords and memorable passphrases with customizable options including length, character types, emojis, and automatic strength evaluation using zxcvbn scoring.
  • F
    license
    Not graded
    quality
    D
    maintenance
    Cryptographically secure random number generation and randomized resources, including tools for numbers, strings, dice rolls, UUIDs, and passphrases.
    4
  • A
    license
    Not graded
    quality
    A
    maintenance
    Local, encrypted password vault with AES-256-GCM and PBKDF2, exposing MCP tools for secure credential management, password generation, and search.
    MIT

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/MukundaKatta/password-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server