Install
$ agentstack add skill-jschuller-mcp-server-servicenow-reviewing-update-sets ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Reviewing ServiceNow Update Sets
Review, analyze, and compare update sets before promotion. See references/update-set-fields.md for update types, risk categories, and pre-promotion checklist fields.
Workflows
1. List & Summarize Update Sets
Get an overview of update sets by state with change counts.
Progress checklist (copy into your response):
- [ ] List update sets by state
- [ ] Get change counts for each
- [ ] Summarize by developer and state
- List update sets by state:
`` list_update_sets(state="in progress", limit=20) list_update_sets(state="complete", limit=20) ``
- For each update set, get the change count:
`` list_update_set_changes(update_set_sys_id="", limit=1) ``
- Summarize: name, state, developer, change count, last modified date.
2. Deep Review a Single Update Set
Examine all changes in an update set, categorize by type, and flag risks.
Progress checklist:
- [ ] Get update set details
- [ ] List all customer updates
- [ ] Categorize changes by type
- [ ] Flag risky changes (ACLs, script includes, schema changes)
- [ ] Summarize findings with risk assessment
- Get the update set details:
`` get_update_set(sys_id="") ``
- List all customer updates in the set:
`` list_update_set_changes(update_set_sys_id="", limit=100) ``
- Categorize each change by type (business rule, client script, UI policy, ACL, etc.).
- Flag risky changes — see
references/update-set-fields.mdfor risk categories:
- ACL modifications (security impact)
- Script Includes (shared library changes)
- Table/Column schema changes (data model impact)
- System Properties (global configuration)
- Scheduled Jobs (background automation)
- Present a summary: total changes, breakdown by type, risk flags with explanations.
3. Compare Two Update Sets
Find overlapping records and potential conflicts between two update sets.
Progress checklist:
- [ ] Get changes for update set A
- [ ] Get changes for update set B
- [ ] Find overlapping records (same target name/table)
- [ ] Identify potential conflicts
- [ ] Report overlap and conflict details
- Get all changes from both update sets:
`` list_update_set_changes(update_set_sys_id="", limit=100) list_update_set_changes(update_set_sys_id="", limit=100) ``
- Compare the change lists:
- Overlapping records: same
target_namemodified in both sets - Conflicting changes: same record with different modifications
- Dependency issues: Set A modifies a record that Set B depends on
- Present: overlapping records, conflict details, recommended promotion order.
4. Pre-Promotion Checklist
Validate an update set is safe to promote using a structured checklist.
Progress checklist:
- [ ] Verify state is "complete"
- [ ] Check for Default update set entries mixed in
- [ ] Scan for test/personal artifacts
- [ ] Check for incomplete references
- [ ] Flag risky change types
- [ ] Generate promotion readiness report
- Get the update set and verify state:
`` get_update_set(sys_id="") ``
- List all changes:
`` list_update_set_changes(update_set_sys_id="", limit=100) ``
- Run pre-promotion checks:
- State: Must be
complete(notin progress) - Default set entries: Flag any changes that belong to the Default update set
- Test artifacts: Look for names containing "test", "debug", "temp", "TODO"
- Personal artifacts: Check for developer-specific names or comments
- Risky types: Flag ACLs, schema changes, system properties
- Incomplete references: Changes that reference records not in the same set
- Generate a promotion readiness report: pass/fail for each check, overall recommendation.
Tips
- Update sets in
ignorestate are intentionally excluded from promotion — don't flag them. - The
sys_update_xmltable stores the actual XML payload of each change. Query it for detailed diffs. - Use
order_by="-sys_created_on"to see the most recent update sets first. - See
references/update-set-fields.mdfor the full list of change types and risk categories.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: jschuller
- Source: jschuller/mcp-server-servicenow
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.