Your AI-powered coding companion for Claude Desktop - MCP server with 23+ development tools
code-buddy is a comprehensive development toolkit with 28 tools covering file operations, git, docker, HTTP, and code analysis. However, the implementation exhibits significant gaps in description quality, schema completeness, and error handling guidance. While tool names follow verb_noun conventions well (analyze_code, format_code, run_command, etc.), many descriptions are terse or generic, and critical security/output documentation is largely absent. Parameter descriptions exist but lack detail on constraints, formats, and ranges. Output schemas are undocumented for most tools, LLMs cannot predict what fields to expect. Error handling is minimal: most tools return raw exceptions rather than actionable recovery guidance. The 'run_command', 'run_python', 'docker_tool', and HTTP tools are particularly dangerous, they accept powerful inputs but provide no warnings about irreversible side effects or permission checks. This is a functional toolkit but falls short of production-grade quality.
Analyze code file and provide statistics
Copies a file from one path to another
Creates a directory at the specified path (can be absolute or relative to project).
Make HTTP requests using curl command
Deletes a directory at the specified path within the project.
Deletes a file at the specified path
Build Docker image
run docker-compose commands
Run docker commands
Missing or vague output schema documentation for 24+ tools. LLMs cannot plan downstream tool calls or extract required fields if they don't know the response structure.
Dangerous tools (run_command, run_python, docker_tool, http_request_tool, curl_tool, delete_file, delete_directory) lack confirmation/dry-run patterns and do not warn about irreversible side effects. Agents can accidentally destroy data or execute unintended commands.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-21 | F | 49 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 43 | - | v1 |
Edit a file by replacing specific content
Find and replace text in a single file
Find and replace text across multiple files
Format a Python file using black
Gets the directory tree structure starting from the specified path within the project.
Extract function and class definitions from a Python file
Run git commands
Show git diff
Show git commit history
Get git status of the project
Make HTTP requests to specified URLs
Lint a Python file using ruff or flake8
Lists files and directories at the specified path within the project.
Moves a file from one path to another
Reads the content of a text file at the specified path
Run a shell command in the project directory
Run a Python script or code
Search for text or pattern across project files
Writes content to a text file at the specified path
Error messages are generic exception strings with no recovery guidance. 'Error: [stack trace]' does not tell an LLM whether to retry, ask the user, or treat as fatal.
Parameter descriptions lack specificity on constraints, formats, and allowed values. E.g., 'timeout' parameters have no minimum/maximum; 'command' parameters accept any string with no sanitization guidance or command injection warnings.
Generic tool names 'docker_tool' and 'curl_tool' are ambiguous. Names like 'docker_tool' do not convey what action is performed (run, build, compose, push, pull?). Rename to verb_noun convention: 'run_docker_command', 'execute_curl_request'.
No permission gates or security boundaries. Tools like 'delete_file' and 'run_command' accept any input from an agent with no validation that the agent has authority to perform those actions.
No audit logging or traceability. Destructive operations (delete_file, delete_directory, run_command) do not log who called them, what parameters were used, or what happened.
Timeout parameters are present but lack constraints. 'timeout' in run_command defaults to 60s with no documented min/max, agents could specify unreasonable timeouts (0, 999999) causing hanging or resource exhaustion.
Path traversal vulnerability risk. Tools accept filepath parameters validated via PathValidator, but descriptions do not explain restrictions (e.g., 'relative paths only', 'no .. allowed'). LLMs may attempt to access files outside project root.
No result limits or pagination for list_directory and search_in_files. Returning thousands of results would exceed context window and waste tokens. Descriptions should state max limits and require pagination.