Atlas / MCP servers / aartiq / ServiceNow Integration

ServiceNow IntegrationBLOCK

mcp/aartiq/servicenow-integration

ServiceNow MCP server: 500+ tools and 26 AI capabilities for any AI (Claude, ChatGPT, Gemini, Cursor, Copilot). Multi-transport (stdio, SSE, HTTP), A2A, dynamic schema discovery, read-only by default. Free and source available. Part of the NowAIKit suite.

Verdict
BLOCK
Grade
F
Trust score
50 /100
Exposed tools
200 366r · 207w · 11d
Transport
sse · stdio · streamable-http
License
NOASSERTION
Stars
264
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/nowaikit) [](docs/TOOLS.md) [](https://modelcontextprotocol.io) [](LICENSE)

Connect Claude, ChatGPT, Gemini, Cursor, Copilot, or any AI, to ServiceNow.

500+ tools across ITSM, ITOM, CMDB, HRSD, CSM, Flow Designer, scripting & portal. Read, build, query and automate any instance in plain English.

New in 4.4 to 4.7: impact analysis (listtableconfig / findfieldreferences / findscriptreferences) to see what depends on a table, field or script before you change it, Local Sync to pull artifacts to local files, and aggregate_report for server-side reports (count plus averages, no truncation).

🚀 Install (2 minutes)

Requires Node.js 20+.
# 1 — install
npm install -g nowaikit

# 2 — run the wizard: it detects your AI clients and writes their config for you
npx nowaikit setup

Restart your AI client (Claude Desktop, Cursor, ...) and start asking. Done.

Prefer a UI? npx nowaikit web for a local dashboard — or use [NowAIKit Cloud](https://cloud.nowaikit.com) (nothing to install).

🔌 Manual setup (skip the wizard)

Add this to your client's MCP config (Claude Desktop claude_desktop_config.json, Cursor ~/.cursor/mcp.json, etc.):

{
"mcpServers": {
"nowaikit": {
"command": "npx",
"args": ["-y", "nowaikit"],
"env": {
"SERVICENOW_INSTANCE_URL": "https://yourcompany.se
Read from source at commit e01ed8164e42OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add nowaikit -- npx -y [email protected]
03

Exposed tools (200)

366 read · 207 write · 11 destructive. Blast radius: 11 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
DevOpsreadPipelines, deployments, DevOps insights.
NowAIKitreadThe most comprehensive ServiceNow AI toolkit: 500+ tools covering ITSM, CMDB, HRSD, CSM, SecOps, GRC, DevOps, and more.
SummarizerreadSummarizes text
actionreadassess, prepare-cab, check-conflicts, plan-rollback. Default: assess
add_adhoc_approverwriteAdd an ad-hoc approver to an in-flight approval on a record (inserts a sysapproval_approver row). Requires WRITE_ENABLED=true
add_commentwriteAdd a customer-visible comment to any ITSM record (requires WRITE_ENABLED=true)
add_roster_memberwriteAdd a member to an on-call roster (cmn_rota_member). Requires WRITE_ENABLED=true
add_user_to_groupwriteAdd a user to a group (requires WRITE_ENABLED=true)
add_work_notewriteAdd an internal work note to any ITSM record (requires WRITE_ENABLED=true)
advance_hr_casereadAdvance an HR case to its next state/stage (sn_hr_core_case). Parity with ServiceNow HRSD
aggregate_reportreadServer-side aggregate REPORT grouped by a field, in ONE query with no 1000-row truncation. Returns per-group record count PLUS averages/sums/mins/maxes of numeric or duration fields — the right tool for a periodic summary like
ai_searchreadSemantic AI-powered search across KB, catalog, incidents (ServiceNow AI Search)
analyze_data_qualityreadAnalyse data quality for a table — completeness, duplicates, stale records
api_namereaddesired API name (e.g.
appreadscoped app name or scope prefix e.g. x_myco_app
app_namereadapplication name
approve_requestreadApprove a pending approval request (requires WRITE_ENABLED=true)
artifactreadPaste code, provide a sys_id, or name a business rule/script include/client script/widget/flow action
artifact_typereadartifact type to test
assign_user_criteriareadAttach a user criteria to a catalog item as available-for (sc_cat_item_user_criteria_mtom). Requires WRITE_ENABLED=true
batch_requestwriteExecute multiple ServiceNow REST API operations in a single HTTP call.
build-appreadBuild a complete scoped application from scratch — tables, scripts, ACLs, catalog item, tests, and update set packaging
build-atf-suitereadAI-generates runnable ATF test suites from business rules, script includes, flows, or any ServiceNow artifact
build-business-rulereadGuided business rule creation — understand requirement, check existing rules, generate, review, create, and test
build-catalogreadEnd-to-end catalog item creation — variables, UI policies, client scripts, approval rules, fulfillment workflow
build-client-scriptreadGuided client script creation — onChange, onLoad, onSubmit with g_form/g_user best practices and GlideAjax patterns
build-flowreadGuided Flow Designer creation — triggers, actions, subflows, error handling, testing
build-portalreadGuided Service Portal widget creation — server script, client controller, HTML template, CSS, data brokers
build-rest-apireadGuided Scripted REST API endpoint design — authentication, input validation, versioning, error responses
build-test-planreadGenerate comprehensive ATF test suites from requirements or existing artifacts — covers all testable ServiceNow components
build-uibreadGuided UI Builder component creation — macroponents, data sources, responsive layouts, Next Experience
bulk_create_recordswriteCreate many records in one table in a single call, tracking every created sys_id and returning a rollback_token. With rollback_on_error=true, a mid-way failure deletes everything already created so the batch is all-or-nothing. Supports dry_run. Requires WRITE_ENABLED=true.
bulk_get_propertiesreadRetrieve multiple system property values in a single call
bulk_set_propertieswriteCreate or update multiple system properties in a single operation. **[Write]**
categorize_incidentreadSuggest category, assignment group, and priority for an incident by analysing similar resolved incidents (Table API). Predictive Intelligence has no public REST prediction endpoint; for model-based scoring run PI on-record and read the predicted field.
categoryreadcatalog category (e.g., Hardware, Software, Access, Services)
changereadchange number e.g. CHG0012345 or describe the planned change
change_readinessreadOne-call change readiness check. Returns the change request, its conflict status, approval state, affected CIs, and other active changes that overlap the same CI. Read-only.
check_hr_eligibilityreadCheck an employee\
check_table_completenessreadAnalyze data quality and field completeness for a ServiceNow table —
ci-healthreadCMDB health check for a named CI
ci_classreadLimit scan to a specific CI class (e.g.
ci_namereadName or sys_id of the Configuration Item
clone_artifactreadClone a platform artifact to a new name/scope. **[Scripting]**
close_change_requestreadClose a change request with close code and notes (requires WRITE_ENABLED=true)
close_csm_casereadClose a CSM case with resolution details (requires WRITE_ENABLED=true)
close_hr_casereadClose an HR case with resolution notes (requires WRITE_ENABLED=true)
close_incidentreadClose a resolved incident (requires WRITE_ENABLED=true)
cmdb_find_duplicatesreadFind duplicate CIs by matching on specified fields (in-memory grouping)
cmdb_find_orphansreadFind CIs with no relationships in cmdb_rel_ci
cmdb_find_stalereadFind CIs not updated within a given number of days that are still operational
cmdb_find_unmapped_cisreadFind operational CIs that have relationships but belong to no application service (mapping gaps). Parity with ServiceNow get_unmapped_topology
cmdb_health_dashboardreadGet CMDB data quality metrics (completeness of server and network CI data)
cmdb_impact_analysisreadAnalyze the downstream impact of a Configuration Item change or outage
cmdb_reconciledestructiveAct on duplicate, stale, or orphan CIs — merge, retire, or remove (requires CMDB_WRITE_ENABLED). Supports dry_run mode.
cmdb_services_for_cireadReverse lookup: which application services contain a given CI/server (svc_ci_assoc). Parity with ServiceNow get_all_application_services_for_a_server
commit_changesetwriteCommit an update set (requires SCRIPTING_ENABLED=true)
compare_instancesreadCompare two configured ServiceNow instances: record counts for a table (with optional query) and/or a specific system property value. Useful for dev→prod drift detection and governance.
compare_record_countsreadCompare record counts across multiple ServiceNow tables or time periods — useful for capacity planning
complete_catalog_taskreadClose a catalog fulfillment task (sc_task) as complete. Requires WRITE_ENABLED=true
complete_taskreadMark a task as complete (requires WRITE_ENABLED=true)
complete_update_setwriteMark an Update Set as complete (ready for migration). **[Scripting]**
component_typereadpage, macroponent, data_resource. Default: macroponent
configure_offline_syncwriteConfigure which tables/records are available offline in mobile. **[Write]**
configure_workspace_listwriteAdd or update a list view in an agent workspace. **[Write]**
copy_attachmentreadCopy an existing ServiceNow attachment onto another record, entirely server-side
coveragereadCoverage level: basic (happy path), standard (happy + edge cases), comprehensive (all paths + negative). Default: standard
create-incidentwriteGuided incident creation — asks for details then creates the record
create_aclwriteCreate a new ACL rule to control access to a table or field (requires SCRIPTING_ENABLED=true)
create_agentic_workflowwriteCreate an agentic workflow linked to an AI agent (requires NOW_ASSIST_ENABLED + WRITE_ENABLED)
create_ai_agentwriteCreate an AI agent definition with optional auto-generated ACLs (requires NOW_ASSIST_ENABLED + WRITE_ENABLED)
create_approval_rulewriteCreate an approval rule that automatically generates approval requests when a record matches given conditions (requires WRITE_ENABLED=true).
create_assetwriteCreate a new IT asset record. **[Write]**
create_business_rulewriteCreate a new business rule (requires SCRIPTING_ENABLED=true). ServiceNow supports ES2021 async/await in scripts.
create_business_servicewriteCreate a business service (cmdb_ci_service). Requires WRITE_ENABLED=true
create_catalog_categorywriteCreate a catalog category (sc_category). Requires WRITE_ENABLED=true
create_catalog_itemwriteCreate a new service catalog item (requires WRITE_ENABLED=true)
create_catalog_ui_policywrite[Write] Create a UI policy for a catalog item form
create_catalog_variablewrite[Write] Add a form variable to a service catalog item
create_change_requestwriteCreate a new change request (requires WRITE_ENABLED=true)
create_ci_relationshipwrite[Write] Create a relationship between two CMDB Configuration Items
create_client_scriptwriteCreate a new client script (onLoad, onChange, onSubmit, onCellEdit) (requires SCRIPTING_ENABLED=true)
create_csm_casewriteCreate a new Customer Service case (requires WRITE_ENABLED=true)
create_dashboardwriteCreate a new Performance Analytics dashboard (requires WRITE_ENABLED=true)
create_decision_inputwriteAdd an input to a decision table (sys_decision_input). Requires WRITE_ENABLED=true
create_decision_tablewriteCreate a Decision Builder decision table (sys_decision). Requires WRITE_ENABLED=true
create_delegationwriteCreate an approval/coverage delegation (sys_user_delegate). Requires WRITE_ENABLED=true
create_demandwriteCreate an SPM demand (dmn_demand). Requires WRITE_ENABLED=true.
create_devops_changewriteCreate a change request linked to a DevOps deployment for change governance. **[Write]**
create_epicwriteCreate a new epic (requires WRITE_ENABLED=true)
create_flowwriteCreate a new Flow Designer flow. **[Write]**
create_flow_actionwriteCreate a custom Flow Designer action. **[Scripting]**
create_grc_controlwriteAuthor a compliance control (sn_compliance_control). Requires WRITE_ENABLED=true
create_grc_issuewriteRaise a GRC issue/finding (sn_grc_issue). Requires WRITE_ENABLED=true
create_grc_riskwriteCreate a new GRC risk entry. **[Write]**
create_groupwriteCreate a new assignment group (requires WRITE_ENABLED=true)
create_hr_casewriteCreate a new HR Service Delivery case (requires WRITE_ENABLED=true)
create_hr_taskwriteCreate a task within an HR case (requires WRITE_ENABLED=true)
create_import_set_rowwriteInsert a row into an Import Set staging table for later transformation (requires WRITE_ENABLED=true)
create_incidentwriteCreate a new incident record (requires WRITE_ENABLED=true)
create_knowledge_articlewriteCreate a new knowledge article (requires WRITE_ENABLED=true)
create_kpiwrite[Write] Create a Key Performance Indicator from ServiceNow data
create_mobile_app_configwriteCreate a new mobile app configuration. **[Write]**
create_mobile_appletwriteCreate a mobile applet in a mobile app. **[Write]**
create_mobile_layoutwriteCreate a mobile layout for a specific view. **[Write]**
create_notificationwriteCreate a new email notification definition (requires WRITE_ENABLED=true)
create_now_assist_skillwriteCreate a Now Assist skill definition (requires NOW_ASSIST_ENABLED + WRITE_ENABLED)
create_offboarding_casewriteCreate an employee offboarding case with exit tasks. **[Write]**
create_on_call_overridewriteCreate an on-call coverage override for a date range (cmn_rota_override). Requires WRITE_ENABLED=true
create_onboarding_casewriteCreate an employee onboarding case with all standard tasks. **[Write]**
create_pa_breakdownwriteCreate a Performance Analytics (PA) breakdown on
create_pa_indicatorwriteCreate a Performance Analytics (PA) indicator / KPI on
create_playbookwriteCreate a playbook definition with ordered steps that chain tool calls (requires NOW_ASSIST_ENABLED + WRITE_ENABLED)
create_portalwriteCreate a new Service Portal configuration (requires WRITE_ENABLED=true)
create_portal_pagewriteCreate a new page inside a Service Portal (requires WRITE_ENABLED=true)
create_portal_widgetwriteCreate a new Service Portal widget with template, CSS, and scripts (requires WRITE_ENABLED=true)
create_problemwriteCreate a new problem record (requires WRITE_ENABLED=true)
create_projectwriteCreate a SPM project (pm_project). Requires WRITE_ENABLED=true.
create_recordwriteCreate a new record in any ServiceNow table (requires WRITE_ENABLED=true). Pass dry_run=true to preview the resolved payload without writing.
create_reportwriteCreate a new saved report on any table (requires WRITE_ENABLED=true)
create_rest_messagewriteCreate a new outbound REST Message definition (requires WRITE_ENABLED=true)
create_rolewriteCreate a new role (sys_user_role). Requires WRITE_ENABLED=true
create_rota_schedulewriteCreate an on-call rotation (cmn_rota) for a group. Requires WRITE_ENABLED=true
create_scheduled_jobwriteCreate a new scheduled script execution job (requires WRITE_ENABLED=true)
create_scheduled_reportwrite[Write] Schedule a report for recurring email delivery
create_scoped_appwriteCreate a new scoped application in App Studio (requires WRITE_ENABLED=true).
create_script_includewriteCreate a new script include (requires SCRIPTING_ENABLED=true)
create_scrum_taskwriteCreate a scrum task (sub-task of a story) (requires WRITE_ENABLED=true)
create_security_incidentwriteCreate a Security Operations incident (requires WRITE_ENABLED=true)
create_service_offeringwriteCreate a service offering under a business service (service_offering). Requires WRITE_ENABLED=true
create_sla_definitionwriteCreate an SLA/OLA definition (contract_sla). Requires WRITE_ENABLED=true
create_solution_packagewriteCreate a solution package from selected update sets for distribution. **[Write]**
create_storywriteCreate a new agile story/user story (requires WRITE_ENABLED=true)
create_story_dependencywriteLink one agile story as dependent on another (m2m_story_dependencies). Requires WRITE_ENABLED=true.
create_subflowwriteCreate a new reusable subflow. **[Write]**
create_surveywriteCreate a survey/assessment definition (asmt_metric_type). Requires WRITE_ENABLED=true
create_ui_actionwriteCreate a new UI Action (button or link) on a form (requires SCRIPTING_ENABLED=true)
create_ui_policywriteCreate a new UI Policy to control field behavior dynamically (requires SCRIPTING_ENABLED=true)
create_uib_componentwriteCreate a custom UI Builder component (macroponent). **[Scripting]**
create_uib_data_brokerwriteCreate a UI Builder data broker to feed data to a page. **[Scripting]**
create_uib_pagewriteCreate a new UI Builder page with route registration. **[Write]**
create_update_setwriteCreate a new Update Set and optionally switch to it. **[Scripting]**
create_userwriteCreate a new user account (requires WRITE_ENABLED=true)
create_user_criteriawriteCreate a user criteria record (user_criteria) for catalog entitlement/audience. Requires WRITE_ENABLED=true
create_ux_app_routewriteRegister a new route (URL path) in a UX app. **[Write]**
create_ux_experiencewriteCreate a new UX Experience (app shell) configuration. **[Write]**
create_va_topicwriteCreate a new Virtual Agent conversation topic. **[Write]**
create_workspacewriteCreate a new configurable agent workspace. **[Write]**
deactivate_userreadDeactivate (offboard) a user by setting active=false. Requires WRITE_ENABLED=true
delete_attachmentdestructiveDelete an attachment from a record (requires WRITE_ENABLED=true)
delete_recorddestructiveDelete a record from any ServiceNow table (requires WRITE_ENABLED=true). Pass dry_run=true to preview the record that would be deleted without deleting it.
delete_story_dependencydestructiveRemove a story dependency link by its m2m_story_dependencies sys_id. Requires WRITE_ENABLED=true.
delete_system_propertydestructiveDelete a system property by name. **[Write]**
delete_uib_pagedestructiveDelete a UI Builder page. **[Write]**
deploy-updatesetwritePreview and commit an update set
descriptionreadwhat the app does
discover_tablereadDiscover a ServiceNow table schema and register dynamic CRUD tools for it.
docs-appreadAuto-generate comprehensive documentation for a scoped application — tables, scripts, flows, ACLs, catalog items, and architecture
docs-releasewriteGenerate release notes from update set contents — summarize all changes, categorize by type, highlight breaking changes
docs-runbookreadGenerate operational runbook for a service, application, or CI — incident response steps, health checks, escalation paths
docs-scriptreadGenerate detailed documentation for a specific script — JSDoc, explanation, usage examples, dependencies
ensure_active_update_setwriteEnsure an active Update Set exists; create one automatically if none is in progress. **[Scripting]**
execute_background_scriptwriteExecute a background script on the instance (server-side JavaScript). **[Scripting]**
execute_playbookwriteExecute a playbook step by step, passing results forward through context (requires NOW_ASSIST_ENABLED). Supports dry_run.
execute_scriptwriteExecute a server-side script on the ServiceNow instance (Background Script).
export_propertiesreadExport system properties matching a query to a JSON object (useful for environment snapshots)
export_report_datareadExport raw table data as structured JSON for use in external reports
export_update_setwriteGet the XML export payload for an Update Set (as used in migration). **[Scripting]**
fetch_servicenow_docreadFetch the full readable text of a specific ServiceNow documentation page. Pass either the
fieldreadfield name for onChange scripts
find_artifactreadSearch for platform artifacts by name, type, or scope (business rules, scripts, widgets, etc.)
find_property_usagereadFind scripts that read a system property (sys_properties) by name, plus the property record itself. Use it before changing or removing a property. Matches are substring (LIKE) hits — candidates to review, not definitive.
find_update_setswriteList the update sets that contain changes to an artifact (by name), so you know what is in-flight or already captured for promotion before you touch it.
fire_eventreadFire a custom ServiceNow event for a specific record (requires WRITE_ENABLED=true)
fluent_buildreadBuild a ServiceNow fluent/now-sdk project. Runs
fluent_cicdwriteRun ServiceNow CI/CD operations via the SDK (
fluent_explainwriteRun
fluent_initreadInitialize a new ServiceNow fluent/now-sdk project. Runs
fluent_queryreadGlideQuery-style fluent query builder. Supports select, where, aggregate (COUNT/AVG/SUM/MIN/MAX),
fluent_sdk_querywriteRun
fluent_validatereadValidate a ServiceNow fluent/now-sdk project. Runs
fluent_versionreadReport the installed
focusreadReview focus: security, performance, best-practices, upgrade-safety, or all (default: all)
fulfillment_typereadflow, workflow, approval_only. Default: flow
generate_case_activity_responsereadDraft an agent reply for a CSM case activity stream via the Now Assist activity-response skill when available, else return the case context to draft from. Parity with ServiceNow CSM
generate_csm_resolution_notesreadGenerate CSM resolution notes via the Now Assist resolution-notes skill when available, else return the case + work notes to summarize. Parity with ServiceNow CSM
get_aclreadGet full details of an ACL rule including its script and role requirements (requires SCRIPTING_ENABLED=true)
get_ai_agentreadGet an AI agent definition and its related ACLs
get_ai_agent_executionreadGet an AI Agent execution plan with its steps/tool calls (sn_aia_execution_plan + _step)
get_approval_historyreadGet the approval progression/history for any record (sysapproval_approver rows, ordered)
get_assetreadGet full details of an IT asset including financial and lifecycle data
get_atf_failure_insightreadGet ATF Failure Insight data — metadata changes between last successful and failed run (role changes, field value changes)
get_atf_suitereadGet details of a test suite including test count
get_atf_suite_resultwriteGet the results of a test suite run
get_atf_testreadGet details of a specific test case
get_attachment_metadatareadGet metadata (name, type, size) of a specific attachment by its sys_id
get_business_rulereadGet full details and script body of a business rule (requires SCRIPTING_ENABLED=true)
get_case_sentimentreadAssess customer sentiment on a CSM case via the Now Assist sentiment skill when available, else return the case + customer comments for sentiment analysis. Parity with ServiceNow CSM
get_catalog_itemreadGet full details of a catalog item including its variables
get_change_requestreadGet full details of a change request by number (CHG...) or sys_id
04

Trust audit

BLOCKgrade F · trust 50/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (12 observation(s))
Shell
declared (10 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/prompts/capabilities/build-app.ts:193
'- No `eval()` or dynamic script execution.',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/prompts/capabilities/build-business-rule.ts:73
'- No `eval()` or dynamic script execution.',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/prompts/capabilities/review-code.ts:86
'- **Injection risks** — `eval()`, `GlideEvaluator` with untrusted input, SQL-like string concatenation in queries',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/prompts/capabilities/review-flows.ts:250
'- Inline Script steps with `eval()`, `GlideEvaluator`, or `Packages.java.*`',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/prompts/capabilities/review-scripts.ts:73
'- `eval()` or `GlideEvaluator` with user-controlled input',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
desktop/resources/icon.icns
icon.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli/auth.ts:292
console.log(chalk.green(`  ✓ Stored token for ${chalk.bold(stored.snUser)}`) + expiredNote);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli/auth.ts:401
console.log(chalk.yellow(`No token found for ${instanceUrl}`));
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/generate-sample-reports.mjs:550
Impact: Any authenticated user can call these server-side functions; DataExporter could be used for data exfiltration
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
desktop/serve.cjs:87
if (origin.startsWith(`http://localhost:${PORT}`) || origin.startsWith(`http://127.0.0.1:${PORT}`)) return true;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
desktop/serve.cjs:89
if (origin.startsWith('http://localhost:5173') || origin.startsWith('http://127.0.0.1:5173')) return true;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/cli/auth.ts:45
const u = new URL(req.url || '/', `http://127.0.0.1:${port}`);
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
cmdb_reconcile, delete_attachment, delete_record, delete_story_dependency, delete_system_property, delete_uib_page, http_methods, list_acls, remove_user_from_group, revoke_role, rollback_changes
Why it matters. 11 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
clients/codex/.env.basic.example
.env.basic.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
clients/codex/.env.oauth.example
.env.oauth.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
clients/gemini/.env.basic.example
.env.basic.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
clients/gemini/.env.oauth.example
.env.oauth.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/generate-sample-reports.mjs:10
const OUTPUT_DIR = resolve(import.meta.dirname, '../../../website-nowaikit/assets/reports');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/writers/index.ts:60
const pkgDir = fileURLToPath(new URL('../../../', import.meta.url)).replace(/[\\/]$/, '');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/a2a/agent-card.test.ts:2
import { buildAgentCard } from '../../src/a2a/agent-card.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/a2a/agent-card.test.ts:3
import { VERSION } from '../../src/utils/version.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/cli/client-paths.test.ts:3
import { detectClients } from '../../src/cli/detect-clients.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
clients/lovable/SETUP.md:21
# Listening on http://127.0.0.1:3100
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/a2a/agent-card.test.ts:87
expect(card.url).toBe('http://0.0.0.0:8080');
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
desktop/package.json
electron-store, electron-updater, @types/react, @types/react-dom, @vitejs/plugin-react, concurrently, electron, electron-builder
Why it matters. 16 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha e01ed8164e42full audit observations/trust-audit/mcp-server/aartiq__servicenow-integration.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06e01ed8164e42BLOCKF50first audit
06

Questions

What is the ServiceNow Integration MCP server?

ServiceNow MCP server: 500+ tools and 26 AI capabilities for any AI (Claude, ChatGPT, Gemini, Cursor, Copilot). Multi-transport (stdio, SSE, HTTP), A2A, dynamic schema discovery, read-only by default. Free and source available. Part of the NowAIKit suite.

What tools does ServiceNow Integration expose?

200 in total: 366 read-only, 207 that write, and 11 that can delete or overwrite (cmdb_reconcile, delete_attachment, delete_record, delete_story_dependency, delete_system_property). Every one is listed on this page with its risk.

Is ServiceNow Integration safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (50/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 11 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does ServiceNow Integration need?

It reads DELEGATED_AUTH, GEMINI_API_KEY, NOWAIKIT_API_KEY, NOWAIKIT_DELEGATED_SECRET, NOWAIKIT_OAUTH_PORT, OPENAI_API_KEY, SERVICENOW_AUTH_METHOD, SERVICENOW_BASIC_PASSWORD, SERVICENOW_BEARER_TOKEN, SERVICENOW_CLIENT_SECRET, SERVICENOW_OAUTH_CLIENT_ID and SERVICENOW_OAUTH_CLIENT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does ServiceNow Integration run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as nowaikit at 4.21.0.

How current is this page?

The grade is for one exact copy of the source (e01ed8164e42), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement