46
/ 100
1 month ago
glama

Service Desk Plus MCP Server

Integrates with Service Desk Plus Cloud API to enable AI assistants to manage IT service requests, technicians, and communications via natural language.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
1 flow detected: SDP_CLIENT_SECRET. We can’t prove the destination matches the brand the credential belongs to.
⚠️
Known vulnerabilities in dependencies: 15 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 10 credentials: ADMIN_API_KEY, DB_PASSWORD, ENCRYPTION_KEY, JWT_SECRET, REDIS_PASSWORD, SDP_CLIENT_SECRET, SDP_OAUTH_CLIENT_SECRET, SDP_OAUTH_REFRESH_TOKEN, SDP_REFRESH_TOKEN, SESSION_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies15 high14 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.0.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.0.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

highaxios@1.10.0GHSA-35jp-ww65-95wh

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

highaxios@1.10.0GHSA-3g43-6gmg-66jw

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

highaxios@1.10.0GHSA-43fc-jf86-j433

Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configADMIN_API_ENABLED
🔐 secretADMIN_API_KEY
configADMIN_PORT
configDB_HOST
configDB_NAME
🔐 secretDB_PASSWORD
configDB_POOL_MAX
configDB_POOL_MIN
configDB_PORT
configDB_SSL
configDB_USER
configENABLE_PLAYGROUND
configENABLE_SWAGGER
configENABLE_TRACING
🔐 secretENCRYPTION_KEY
configHEALTH_CHECK_INTERVAL_MS
configHOST
🔐 secretJWT_SECRET
configLOG_COMPRESS
configLOG_FILE_PATH
configLOG_FORMAT
configLOG_LEVEL
configLOG_MAX_FILES
configLOG_MAX_SIZE
configLOG_TO_CONSOLE
configMAX_TENANTS
configMCP_CORS_ORIGIN
configMCP_HEARTBEAT_INTERVAL
configMCP_MAX_CONNECTIONS
configMCP_SERVER_PATH
configMCP_SERVER_PORT
configMCP_TCP_HOST
configMCP_TCP_PORT
configMETRICS_ENABLED
configMETRICS_PORT
configMOCK_SDP_PORT
configPORT
configRATE_LIMIT_MAX_REQUESTS
configRATE_LIMIT_PER_TENANT
configRATE_LIMIT_WINDOW_MS
configREDIS_DB
configREDIS_HOST
🔐 secretREDIS_PASSWORD
configREDIS_PORT
configREDIS_TLS
configREMOTE_HOST
configREMOTE_PORT
configSCOPE_VALIDATION_ENABLED
configSDP_API_VERSION
configSDP_BASE_URL
configSDP_CLIENT_ID
🔐 secretSDP_CLIENT_SECRET
configSDP_DATA_CENTERUS # Data center (US, EU, IN, AU, JP, UK, CA, CN)
configSDP_DEFAULT_PAGE_SIZE
configSDP_HTTP_HOST
configSDP_HTTP_PORT
configSDP_INSTANCE_NAMEitdesk # Instance name
configSDP_INSTANCE_URL
configSDP_MAX_PAGE_SIZE
configSDP_OAUTH_CLIENT_IDyour_client_id
🔐 secretSDP_OAUTH_CLIENT_SECRETyour_client_secret_here
configSDP_OAUTH_REDIRECT_URI
🔐 secretSDP_OAUTH_REFRESH_TOKENyour_permanent_refresh_token_here
configSDP_PORTAL_NAMEyourportal # Portal name
🔐 secretSDP_REFRESH_TOKEN
configSDP_RETRY_ATTEMPTS
configSDP_RETRY_DELAY_MS
configSDP_TENANT_ID
configSDP_TIMEOUT_MS
configSDP_USE_MOCK
configSDP_USE_MOCK_APIexport =true
configSERVER_ENDPOINTS
🔐 secretSESSION_SECRET
configSSE_URL
configTENANT_CACHE_TTL_SECONDS
configTOKEN_REFRESH_BUFFER_SECONDS
configTRACING_ENDPOINT
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/sk04062025-sdp-mcp-poc-42kx90)](https://m8ven.ai/mcp/sk04062025-sdp-mcp-poc-42kx90)
commit: 32f9233c583ff376d923100b872b256afc001f37
code hash: ffe2532a625c6a3c2fae159956720164ae15aef69613575bd84c16679d5b432f
verified: 6/22/2026, 12:52:45 PM
view raw JSON →