Skip to main content
Glama
sjk4425

ncloud-mcp-server

by sjk4425

ncloud_secret_get_secret_value

Read-only

Retrieve plain-text secret values for all stages (previous, active, pending) from Naver Cloud Secret Manager using a secret ID, with optional global or regional key isolation.

Instructions

Get the secret values of every stage (previous / active / pending). ⚠️ The response contains the secret value in plain text.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
secretIdYesSecret ID (see ncloud_secret_list_secrets)
keyIsolationNoWhich Secret Manager host to call: 'global' (default) for secrets encrypted with a KMS global key (secretmanager.apigw.ntruss.com); 'regional' for secrets encrypted with a KMS region-isolated key (ocapi-kr.ncloud.com/secretmanager — the only option in the JPN region)global

Schema Changelog

Changes observed during successful MCP inspections.

  1. Addedv2.0.1

TDQS

A3.8/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already establish this is a safe read (readOnlyHint=true), so the description's job is lighter. It earns credit by disclosing the non-obvious consequence that the response returns the secret in plain text — a genuine sensitivity warning that no annotation conveys. It omits auth/permission requirements and any masking or logging caveats, keeping it short of a 5.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences, no filler, with the scope statement front-loaded and the security warning isolated with a symbol so it cannot be skimmed past. Every clause carries information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a no-output-schema read tool, the description covers the essential return characteristic (plain-text secret across all stages) and the schema fully documents inputs. It could note which stage is which in the response or any rate/permission constraint, but nothing an agent needs to invoke it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%: secretId points to ncloud_secret_list_secrets and keyIsolation carries a detailed enum explanation of global vs regional KMS hosts. The description adds nothing about either parameter, so the baseline of 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Get the secret values') and pins the scope precisely to 'every stage (previous / active / pending)', which implicitly separates it from ncloud_secret_get_secret_stage_value (single stage). It never names a sibling explicitly, so an agent must infer the boundary rather than being told it.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The 'every stage' phrasing implies usage context, but there is no stated when-to-use, when-not-to-use, or named alternative for the closely related ncloud_secret_get_secret and ncloud_secret_get_secret_stage_value tools. Guidance is present only by inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools