Pod

Available as Markdown and JSON. Pod is also available over MCP.

Reported issues for s2-netbox-mcp

Pod holds 17 of 23 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to s2-netbox-mcp.

Most discussed

Track live-verification status of every MCP tool

Living checklist of which tools have been exercised against the real NetBox 6.2.0 controller. Tick a box when a tool has been run live and its result verified (read-back or observed). Unit tests (428, mocked controller) cover every tool's schema, wire shape, guards, and gating, but a mocked pass is not a live pass — every finding below came from live runs only.

Last updated: 2026-09-15 (after PR #14: npm run test:live:write 38/38 and the supervised single-action session at portal 02OF01A).…

Read the thread · 2026-09-15 · closed · 1 comment

Ship agent guidance: MCP instructions + get_guide tool

Spec: specs/agent-guidance.md

Ship this server's own operating knowledge (S2 NetBox access model, scheduling/naming gotchas, write/destructive safety policy) over the MCP connection itself via a server instructions block and a new always-on get_guide tool, so any connected agent has it immediately with no separate skill install.

Read the thread · 2026-09-22 · closed · 0 comments

NBAPI v2 full conformance: 24 remaining commands, live verification, doc diff, STATUS refresh

Spec: specs/nbapi-v2-full-conformance.md

Wires in the 24 documented NBAPI v2 commands not yet implemented (12 reads, 8 non-destructive writes, 4 destructive), live-verifies the unreleased conformance batch already on main, publishes a three-document command diff report, and refreshes STATUS.md/README.md.

See the spec for the full acceptance rubric (C1-C21 + C-final).

Read the thread · 2026-09-17 · closed · 0 comments

SetThreatLevel missing optional LOCATIONKEYS scoping parameter

Problem

docs/reference/NetBox_API_V2.pdf's SetThreatLevel entry documents an optional LOCATIONKEYS param (comma-separated location keys) that lets a caller scope a threat-level change to specific locations/readers instead of the whole partition.

set_threat_level (src/tools/threatLevel.ts:20-25) sends only LEVELNAME and doesn't expose LOCATIONKEYS at all.

Impact

Since LOCATIONKEYS is optional per the doc, this isn't a correctness bug — command name and required…

Read the thread · 2026-09-16 · closed · 0 comments

AddTimeSpecGroup cannot set initial TIMESPECKEYS membership

Problem

docs/reference/NetBox_API_V2.pdf (doc p.103) documents TIMESPECKEYS/TIMESPECKEY as calling parameters for AddTimeSpecGroup, letting a caller populate a new group's membership at creation time (the doc's own worked example creates a "Maintenance Staff" group with 3 TIMESPECKEYs).

add_time_spec_group (src/tools/timeSpec.ts:144-152) only accepts/sends NAME and DESCRIPTION — it never accepts or forwards TIMESPECKEYS.

Impact

Every group created through this tool…

Read the thread · 2026-09-16 · closed · 0 comments

AddPerson/ModifyPerson missing USERNAME/PASSWORD/ROLE/AUTHTYPE and a few other fields

Problem

docs/reference/NetBox_API_V2.pdf marks USERNAME, ROLE, AUTHTYPE as required fields for AddPerson (doc p.89), with PASSWORD required when AUTHTYPE=DB; the FAIL list (doc p.91) confirms with AddPerson-specific messages ("ROLE is a mandatory field for AddPerson", "Missing ROLE.", "Missing AUTHTYPE."). ModifyPerson (doc p.235) documents the same fields with identical wording. Optional fields MOBILEPHONE/MSUENABLED/BLUEDIAMONDENABLED are also documented for both…

Read the thread · 2026-09-16 · closed · 0 comments

GetThreatLevels command is unimplemented — no way to list threat levels

Problem

src/commands.ts's 80-command allowlist has no GetThreatLevels entry — only SetThreatLevel/AddThreatLevel/AddThreatLevelGroup/ModifyThreatLevel/ModifyThreatLevelGroup/RemoveThreatLevel/RemoveThreatLevelGroup. There is no MCP tool to read threat levels back.

GetThreatLevels is documented in docs/reference/NetBox_API_V2.pdf (doc p.198), with an ALLPARTITIONS filter param and response fields LEVELKEY, SEQNUM, LEVELNAME, COLOR, PARTITIONKEY.

The…

Read the thread · 2026-09-16 · closed · 0 comments

get_reader_access_history drops the native PORTALNAME field from GetAccessHistory records

get_reader_access_history's toAccessHistoryRecord() (src/readerAccessHistory.ts) whitelists 9 fields (LOGID, PERSONID, READER, READERKEY, PORTALKEY, DTTM, NODEDTTM, TYPE, REASON) when mapping each raw ACCESS record. The underlying GetAccessHistory response also carries PORTALNAME on every record (a native NBAPI field, confirmed on get_access_history/get_card_access_details -- see specs/archive/get-access-history-resolve-descriptions.md and specs/archive/get-card-access-details-resolve-names.md,…

Read the thread · 2026-09-16 · closed · 0 comments

Most recent

Add RESOLVEMEMBERNAMES member-name enrichment to get_time_spec_groups

Spec: specs/time-spec-groups-resolve-member-names.md

Let get_time_spec_groups resolve each group's bare TIMESPECKEYS member list into named {TIMESPECKEY, NAME} entries by default (RESOLVEMEMBERNAMES, opt-out, default true), via one full paginated GetTimeSpecs fetch per call. Also relocates the existing keyList bare-value-collection normalizer from src/unlockWindow/managed.ts to the general src/paging.ts module. Scoped to the plural get_time_spec_groups only -- the singular get_time_spec_group…

Read the thread · 2026-09-16 · closed · 0 comments

Add RESOLVEGROUPNAMES group-name enrichment to get_portal_group

Spec: specs/portal-group-resolve-group-names.md

Let get_portal_group resolve its bare UNLOCKTIMESPECGROUPKEY into a human-readable time spec group name by default (RESOLVEGROUPNAMES, opt-out, default true), reusing src/timeSpecGroupNames.ts from #61 (merged via PR #62). Same flag name/semantics as get_access_level's own RESOLVEGROUPNAMES since it's the identical kind of lookup against the same table. THREATLEVELGROUPKEY stays out of scope -- no NBAPI read command exists.

Read the thread · 2026-09-16 · closed · 0 comments

Add RESOLVEGROUPNAMES group-name enrichment to get_access_level

Spec: specs/access-level-resolve-group-names.md

Let get_access_level resolve its bare TIMESPECGROUPKEY/READERGROUPKEY foreign keys into human-readable group names by default (RESOLVEGROUPNAMES, opt-out, default true), reusing new shared modules src/timeSpecGroupNames.ts and src/readerGroupNames.ts. Verified live this session that the singular GetTimeSpecGroup lookup fails NOT FOUND even for an existing group, so resolution must go through the paginated GetTimeSpecGroups list instead.…

Read the thread · 2026-09-16 · closed · 0 comments

Add RESOLVEDESCRIPTIONS reader-description enrichment to get_portals

Spec: specs/get-portals-resolve-descriptions.md

Let get_portals fill in each nested reader's human-readable DESCRIPTION by default (opt-out via RESOLVEDESCRIPTIONS: false), reusing src/readerDescriptions.ts's fetchReaderDescriptions (already merged via PR #54). GetPortals never populates DESCRIPTION on its nested READERS list today, only READERKEY/NAME/PORTALORDER — NAME is a site code, not human-readable.

Read the thread · 2026-09-16 · closed · 0 comments

Add RESOLVENAMES person-name enrichment to get_card_access_details

Spec: specs/get-card-access-details-resolve-names.md

Let callers of get_card_access_details opt in to having the card's owner name resolved alongside the card's access records, reusing the same person-enrichment machinery already built for get_access_history (src/personEnrichment.ts).

The key difference from get_access_history: PERSONID appears exactly once at the top level (a card belongs to one person), so this is a single GetPerson lookup per call, not per-record.

Read the thread · 2026-09-16 · closed · 0 comments

Add RESOLVEDESCRIPTIONS reader-description enrichment to access-record tools

Spec: specs/get-access-history-resolve-descriptions.md

Let the three tools that return raw reader/portal codes (READER/PORTALNAME, e.g. "02RB06") also surface the human-readable READERDESCRIPTION (e.g. "HALLWAY TO ROUND BED AREA") alongside them, by default -- without a second manual lookup.

Covers get_access_history, get_reader_access_history, and get_card_access_details. Introduces src/readerDescriptions.ts, a dependency of the get_portals RESOLVEDESCRIPTIONS spec that follows this one.

Read the thread · 2026-09-16 · closed · 0 comments

Add RESOLVENAMES person-name enrichment to get_access_history

Spec: specs/get-access-history-resolve-names.md

Let callers of get_access_history opt in to having each returned access record enriched with the badge-holder's name (FIRSTNAME/LASTNAME/FULLNAME/NOTES), without changing the tool's existing behavior for anyone who doesn't ask for it.

Also fixes #47: OLDESTDTTM/NEWESTDTTM are removed entirely rather than renamed -- confirmed live this session (controlled A/B test) that even the correct NBAPI field names (STARTDATE/ENDDATE) are silently ignored…

Read the thread · 2026-09-16 · closed · 0 comments

get_access_history: date-range params are wrong (OLDESTDTTM/NEWESTDTTM should be STARTDATE/ENDDATE)

The existing `get_access_history` tool (`src/tools/events.ts`) exposes `OLDESTDTTM`/`NEWESTDTTM` as its date-range filter parameters. These are wrong and have never worked -- confirmed live against the real controller while building #46:

Read the thread · 2026-09-16 · closed · 0 comments

Add get_reader_access_history composite tool

Spec: specs/get-reader-access-history.md

Add a read-only MCP tool that returns a single reader's access (grant/deny) history, with each match's PERSONID enriched to a name -- something the raw GetAccessHistory pass-through cannot do today since it has no reader/portal filter at all. Filtering happens client-side over GetAccessHistory's AFTERLOGID/NEXTLOGID pagination (verified live this session), mirroring the existing find_portals composite-tool pattern.

Motivating case: four readers on the…

Read the thread · 2026-09-16 · closed · 0 comments

The remaining reports are on the project's issue tracker.