Skip to main content
Glama
irrenwill

secret-safe-env

by irrenwill

Server Quality Checklist

67%
Profile completionA complete profile improves this server's visibility in search results.
  • Latest release: v0.1.2

  • Disambiguation5/5

    The two tools have clearly distinct purposes: setting a secret and checking for existence. There is no overlap or ambiguity.

    Naming Consistency5/5

    Both tools follow a consistent verb_noun snake_case pattern (set_env_secret, env_key_exists), making them predictable.

    Tool Count4/5

    With 2 tools, the server is minimal but appropriate for its focused scope of managing .env secrets. However, the count feels slightly low for a full-featured solution.

    Completeness3/5

    The server covers setting and checking existence of secrets but lacks a tool to delete or remove secrets, which is a notable gap for lifecycle management.

  • Average 4.8/5 across 2 of 2 tools scored.

    See the Tool Scores section below for per-tool breakdowns.

    • No community issues in the last 6 months
    • 37 commits in the last 12 weeks
    • Last stable release on
    • No critical vulnerability alerts
    • No high-severity vulnerability alerts
    • No code scanning findings
    • CI status not available
  • This repository is licensed under MIT License.

  • This repository includes a README.md file.

  • No tool usage detected in the last 30 days. Usage tracking helps demonstrate server value.

    Tip: use the "Try in Browser" feature on the server page to seed initial usage.

  • Add a glama.json file to provide metadata about your server.

  • If you are the author, simply .

    If the server belongs to an organization, first add glama.json to the root of your repository:

    {
      "$schema": "https://glama.ai/mcp/schemas/server.json",
      "maintainers": [
        "your-github-username"
      ]
    }

    Then . Browse examples.

  • Add related servers to improve discoverability.

How to sync the server with GitHub?

Servers are automatically synced at least once per day, but you can also sync manually at any time to instantly update the server profile.

To manually sync the server, click the "Sync Server" button in the MCP server admin interface.

How is the quality score calculated?

The overall quality score combines two components: Tool Definition Quality (70%) and Server Coherence (30%).

Tool Definition Quality measures how well each tool describes itself to AI agents. Every tool is scored 1–5 across six dimensions: Purpose Clarity (25%), Usage Guidelines (20%), Behavioral Transparency (20%), Parameter Semantics (15%), Conciseness & Structure (10%), and Contextual Completeness (10%). The server-level definition quality score is calculated as 60% mean TDQS + 40% minimum TDQS, so a single poorly described tool pulls the score down.

Server Coherence evaluates how well the tools work together as a set, scoring four dimensions equally: Disambiguation (can agents tell tools apart?), Naming Consistency, Tool Count Appropriateness, and Completeness (are there gaps in the tool surface?).

Tiers are derived from the overall score: A (≥3.5), B (≥3.0), C (≥2.0), D (≥1.0), F (<1.0). B and above is considered passing.

Tool Scores

  • Behavior4/5

    Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

    Annotations declare readOnlyHint=true and destructiveHint=false, confirming this is a safe read operation. The description adds that it returns only true/false and never the value, which is important behavioral detail beyond the annotations. No contradiction.

    Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

    Conciseness5/5

    Is the description appropriately sized, front-loaded, and free of redundancy?

    The description is extremely concise: two sentences that front-load the core purpose and include key behavioral and usage notes. Every sentence earns its place, with zero wasted words.

    Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

    Completeness5/5

    Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

    With 2 parameters fully described in the schema, a known output schema, comprehensive annotations, and a sibling tool mentioned, the description provides all necessary context. The agent has clear guidance on when and how to use the tool effectively.

    Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

    Parameters4/5

    Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

    Schema coverage is 100%, so the schema already defines the parameters. The description adds value by explaining the default for env_path and relating it to set_env_secret. This context helps the agent use the parameters correctly without repeating schema details.

    Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

    Purpose5/5

    Does the description clearly state what the tool does and how it differs from similar tools?

    The description clearly states the tool checks if an environment variable NAME exists in a .env file and returns only true/false. It distinguishes itself from reading the file directly and mentions the sibling tool set_env_secret, making the purpose unambiguous.

    Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

    Usage Guidelines5/5

    Does the description explain when to use this tool, when not to, or what alternatives exist?

    The description explicitly states when to use this tool—to verify set_env_secret worked—and what to avoid (reading/cat-ing .env). It provides a clear alternative (don't expose secrets), which helps the agent choose correctly.

    Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

  • Behavior5/5

    Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

    The description explains that the agent never sees the value (user types into a masked dialog), the value is written straight to .env, and it must be single-line. This adds significant context beyond the annotations (readOnlyHint=false, destructiveHint=true). No contradiction.

    Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

    Conciseness4/5

    Is the description appropriately sized, front-loaded, and free of redundancy?

    The description is about six sentences, covering all necessary guidance without excessive verbosity. It is front-loaded with the core purpose and immediately transitions to usage rules. Minor redundancy could be trimmed, but overall well-structured.

    Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

    Completeness4/5

    Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

    The description addresses the key behavioral aspects (value invisibility, single-line constraint) and provides alternatives for multi-line secrets. It does not explicitly state what happens if the key already exists (overwrite) or if the .env file does not exist, but these are minor gaps given the overall clarity.

    Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

    Parameters5/5

    Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

    The schema describes both parameters with clear descriptions and examples. The description reinforces that the agent passes only the key name and the user provides the value, and for env_path it explains the default behavior and warns about incorrect defaults when launched via a runner.

    Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

    Purpose5/5

    Does the description clearly state what the tool does and how it differs from similar tools?

    The description clearly states the tool writes secrets/API keys/tokens to a .env file, with concrete examples like 'add my OpenAI key', 'set DATABASE_URL'. It distinguishes from the sibling env_key_exists by focusing on setting values.

    Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

    Usage Guidelines5/5

    Does the description explain when to use this tool, when not to, or what alternatives exist?

    The description explicitly tells when to use the tool (whenever a secret needs to be written) and lists forbidden actions: 'DO NOT ask the user to paste the secret into the chat', 'DO NOT write the value or a placeholder yourself', 'DO NOT cat/read .env to verify (use env_key_exists)'.

    Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

GitHub Badge

Glama performs regular codebase and documentation scans to:

  • Confirm that the MCP server is working as expected.
  • Confirm that there are no obvious security issues.
  • Evaluate tool definition quality.

Our badge communicates server capabilities, safety, and installation instructions.

Card Badge

secret-safe-env MCP server

Copy to your README.md:

Score Badge

secret-safe-env MCP server

Copy to your README.md:

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/irrenwill/secret-safe-env'

If you have feedback or need assistance with the MCP directory API, please join our Discord server