secret-safe-env
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| set_env_secretA | Use this WHENEVER a task needs a secret/API key/token/password/connection string/credential written to a project .env file - e.g. "add my OpenAI key", "set DATABASE_URL", "configure my .env", "save this API token". You pass ONLY the variable NAME; the user types the value into a local masked dialog and it is written straight to .env - you never see or handle the value. DO NOT ask the user to paste the secret into the chat; DO NOT write the value or a placeholder yourself; DO NOT cat/read .env to verify (use env_key_exists). The value must be single-line (not for multi-line PEM keys / JSON blobs - for those, tell the user to edit .env manually). |
| env_key_existsA | Check whether an environment variable NAME already exists in a project .env file. Returns ONLY true/false - never the value. Use this to verify set_env_secret worked, INSTEAD of reading/cat-ing .env (which would expose the secret). |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 2 tools
The two tools have clearly distinct purposes: setting a secret and checking for existence. There is no overlap or ambiguity.
Both tools follow a consistent verb_noun snake_case pattern (set_env_secret, env_key_exists), making them predictable.
With 2 tools, the server is minimal but appropriate for its focused scope of managing .env secrets. However, the count feels slightly low for a full-featured solution.
The server covers setting and checking existence of secrets but lacks a tool to delete or remove secrets, which is a notable gap for lifecycle management.