Atlas / MCP servers / happy-technologies-llc / ServiceNow

ServiceNowCAUTION

mcp/happy-technologies-llc/servicenow-5

Happy Platform MCP v5.1 - Multi-Instance ServiceNow MCP Server

Verdict
CAUTION
Grade
D
Trust score
67 /100
Exposed tools
50 27r · 23w · 0d
Transport
sse · stdio · streamable-http
License
Apache-2.0
Stars
54
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Happy MCP Server

Model Context Protocol Server for the ServiceNow® Platform

A metadata-driven MCP server that auto-generates 480+ tools across 160+ tables, with multi-instance support, natural language search, and local script development.

Website | GitHub | npm | Tools | Contributing | Support

Migrating from `servicenow-mcp-server`? The npm package has been renamed to happy-platform-mcp and the Docker image to nczitzer/happy-platform-mcp. The old names are deprecated but will continue to work temporarily. Update your dependencies: ``bash # npm npm uninstall servicenow-mcp-server && npm install happy-platform-mcp # Docker docker pull nczitzer/happy-platform-mcp:latest ``

Support

If you find this project useful, consider supporting its development. Contributions support Happy Technologies LLC.

#

Read from source at commit 282a23a6175dOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add happy-platform-mcp --env SERVICENOW_PASSWORD=${SERVICENOW_PASSWORD} -- npx -y [email protected]
03

Exposed tools (50)

27 read · 23 write · 0 destructive.

ToolRiskDescription
SN-Add-Change-CommentwriteAdd a comment to a change request. Accepts change number for better UX.
SN-Add-CommentwriteAdd a comment to an incident. Accepts incident number for better UX.
SN-Add-Problem-CommentwriteAdd a comment to a problem. Accepts problem number for better UX.
SN-Add-Work-NoteswriteAdd work notes to an incident. Accepts incident number for better UX.
SN-Approve-ChangereadApprove a change request.
SN-Assign-ChangereadAssign a change request to a user and/or group.
SN-Assign-IncidentreadAssign an incident to a user and/or group. Resolves user names automatically.
SN-Batch-CreatewriteCreate multiple related records in one operation with variable references and transactional support. Reports progress during execution.
SN-Batch-UpdatewriteUpdate multiple records efficiently in a single operation. Reports progress during execution.
SN-Catalog-Get-CategoriesreadList Service Catalog categories so you can browse available form families. Use the returned sys_ids with SN-Catalog-Search-Items to filter forms by category.
SN-Catalog-Search-ItemsreadSearch or browse Service Catalog items and record producers. Use this to discover available forms before calling SN-Catalog-Get-Item to get full form details.
SN-Catalog-SubmitwriteSubmit a Service Catalog form (catalog item or record producer). Provide the catalog item sys_id and a map of variable names to values. Use SN-Catalog-Get-Item first to discover required variables, their types, and valid choices. Returns the resulting request/task numbers.
SN-Clone-Update-SetwriteClone an entire update set with all its sys_update_xml records. Creates a complete copy for backup, testing, or branching development work. Reports progress during cloning operation.
SN-Close-IncidentreadClose an incident with close notes and code.
SN-Close-ProblemreadClose a problem with resolution information.
SN-Create-ActivitywriteCreate a single workflow activity with embedded JavaScript code. Use this for adding activities to existing workflows.
SN-Create-IncidentwriteCreate a new Incident
SN-Create-RecordwriteCreate a record in any ServiceNow table by name. WARNING: For catalog_ui_policy_action table, fields ui_policy and catalog_variable cannot be set via REST API - use SN-Execute-Background-Script with setValue() after creation.
SN-Create-TransitionwriteCreate a transition between two workflow activities with optional condition
SN-Discover-Table-SchemareadDeep schema introspection with ServiceNow-specific metadata including type codes, choice tables, and relationships
SN-Docs-FamiliesreadList available ServiceNow documentation families/releases from the official ServiceNowDocs GitHub repository.
SN-Docs-GetreadRetrieve a ServiceNow documentation markdown document by family and path.
SN-Docs-SearchreadSearch locally synced ServiceNow documentation using SQLite FTS, with optional vector search when enabled.
SN-Docs-StatusreadShow local ServiceNow docs cache, FTS index, and optional vector index status.
SN-Docs-SyncwriteDownload and index a ServiceNowDocs family into the local SQLite FTS cache.
SN-Execute-Background-ScriptwriteExecutes server-side JavaScript by creating a sys_trigger scheduled job that runs in ~1 second and auto-deletes after execution. Use for complex GlideRecord operations the CRUD tools cannot express. The job runs in the scheduler\
SN-Explain-FieldreadGet comprehensive explanation of a specific field including type, constraints, and known issues
SN-Get-Current-InstancereadGet information about the currently active ServiceNow instance
SN-Get-Current-Update-SetwriteGet the currently active update set
SN-Get-IncidentreadGet a Incident by ID
SN-Get-RecordreadGet a specific record from any ServiceNow table by sys_id
SN-Get-Table-SchemareadGet the schema/metadata for any ServiceNow table including required fields, common fields, and field descriptions
SN-Inspect-Update-SetwriteInspect update set contents and verify completeness
SN-List-Available-TablesreadList all available ServiceNow tables with their descriptions and capabilities
SN-List-ChangeRequestsreadList Change Request records with filtering and pagination
SN-List-CmdbCisreadList Cmdb Ci records with filtering and pagination
SN-List-IncidentsreadList Incident records with filtering and pagination
SN-List-ProblemsreadList Problem records with filtering and pagination
SN-List-SysUserGroupsreadList Sys User Group records with filtering and pagination
SN-List-SysUsersreadList Sys User records with filtering and pagination
SN-List-Update-SetswriteList available update sets
SN-Move-Records-To-Update-SetwriteMove sys_update_xml records to a different update set. Supports filtering by sys_ids, time range, or source update set. Extremely useful when records end up in wrong update set (e.g.,
SN-Publish-WorkflowwritePublish a workflow version, setting the start activity and making it active
SN-Query-TablereadQuery any ServiceNow table by name with flexible filtering
SN-Resolve-IncidentreadResolve an incident with resolution notes and code.
SN-Set-Current-ApplicationwriteSet the current application scope using the UI picker and verify the change in the same session. Reports the previous scope; returns an error if the change cannot be verified.
SN-Set-InstancewriteSwitch to a different ServiceNow instance. Use this at the start of your session to target a specific instance (dev, test, prod, etc.). Lists available instances if no name provided.
SN-Set-Update-SetwriteSet the current update set through the ServiceNow UI picker and verify, in the same session, that it took effect. If the automated change fails or cannot be verified, a fix script is written to ./scripts for manual execution instead.
SN-Update-RecordwriteUpdate a record in any ServiceNow table by sys_id
SN-Validate-ConfigurationreadValidate catalog item configuration including variables, UI policies, and business rules
04

Trust audit

CAUTIONgrade D · trust 67/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (6 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/config-manager.test.js:97
secret: 'unit-test-non-secret'
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/config-manager.test.js:374
password: 'legacy-password-fixture',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/config-manager.test.js:457
password: 'legacy-password-fixture',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/config-manager.test.js:468
password: 'legacy-password-fixture',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/config-manager.test.js:532
password: 'configured-password-fixture',
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitleaks.toml
.gitleaks.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitleaksignore
.gitleaksignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/docs-vector-index.test.js:45
exec(sql) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/servicenow-client-background-script-output.test.js:90
expect(() => new Function(generated)).not.toThrow();
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/servicenow-client-background-script-output.test.js:112
expect(() => new Function(generated)).not.toThrow();
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/docs/config.js:10
const DEFAULT_CONFIG_PATH = path.resolve(__dirname, '../../config/servicenow-instances.json');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/bulk-input-bounds.test.js:237
['an invalid table', [{ table: 'incident/../../x', sys_id: hex(1), data: {} }]]
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/docs-github-client.test.js:88
'markdown/../../other/x.md',
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/docs-tools.test.js:117
for (const unsafe of ['../../etc/passwd.md', 'a%2F..%2Fb.md', 'x.md?y', undefined]) {
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/docs-tools.test.js:170
const denied = await client.callTool({ name: 'SN-Docs-Get', arguments: { path: '../../../etc/passwd.md' } });
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:237
proxy_pass http://127.0.0.1:3000;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/DOCKER_DEPLOYMENT.md:110
`/health` requires the bearer token like every other route. The image's `HEALTHCHECK` (and the one in `docker-compose.yml`) reads `HAPPY_MCP_API_TOKEN` from the container environment at run time and c
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/SETUP_GUIDE.md:150
Register `http://127.0.0.1:8202/callback` as the public client's redirect URL. Do not set `SERVICENOW_CLIENT_SECRET` for a public client.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/plans/2026-07-23-instance-registration.md:272
Implement `validateNewInstance(instance)` with the approved invariants. Permit `http://127.0.0.1`, `http://localhost`, and `http://[::1]` only for loopback fixtures. Never include the whole submitted
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
examples/test-sse-keepalive.js:66
console.log(`🚀 SSE Test Server listening on http://127.0.0.1:${PORT}`);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@inquirer/prompts, @napi-rs/keyring, chokidar, dotenv, express, zod, @types/jest, jest
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:22
1. **HTTP/SSE:** generate a token (`openssl rand -hex 32`), set `HAPPY_MCP_API_TOKEN` on the server, and send `Authorization: Bearer <token>` from every HTTP client, probe and health check. Set `HAPPY
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:47
- Bound the SSE lifecycle: 16 pending and 32 active sessions; 30-second setup, 30-minute idle and 12-hour lifetime limits; 8 MiB JSON bodies; one POST at a time per session with up to 8 queued; 8 conc
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:50
- Bind persisted authorization-code refresh tokens to the OAuth identity they were issued for: a versioned `identity-v1-<sha256>` key over the local OS user, canonical instance URL, OAuth client ID, a
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:51
- OAuth authorize/token endpoints must share the instance origin unless the operator lists the external IdP origin in `SERVICENOW_OAUTH_TRUSTED_ORIGINS` (comma-separated exact origins). The policy is
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 282a23a6175dfull audit observations/trust-audit/mcp-server/happy-technologies-llc__servicenow-5.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08282a23a6175dCAUTIOND67first audit
06

Questions

What is the ServiceNow MCP server?

Happy Platform MCP v5.1 - Multi-Instance ServiceNow MCP Server

What tools does ServiceNow expose?

50 in total: 27 read-only, 23 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is ServiceNow safe to connect to an agent?

With care. The audit graded it D (67/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does ServiceNow need?

It reads GH_TOKEN, GITHUB_TOKEN, HAPPY_MCP_API_TOKEN, SERVICENOW_AUTH_TYPE, SERVICENOW_CLIENT_SECRET, SERVICENOW_OAUTH_AUTHORIZE_URL, SERVICENOW_OAUTH_CALLBACK_PATH, SERVICENOW_OAUTH_GRANT_TYPE, SERVICENOW_OAUTH_REDIRECT_PORT, SERVICENOW_OAUTH_SCOPE, SERVICENOW_OAUTH_TOKEN_URL and SERVICENOW_OAUTH_TRUSTED_ORIGINS from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does ServiceNow run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as happy-platform-mcp at 6.0.2.

How current is this page?

The grade is for one exact copy of the source (282a23a6175d), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement