This MCP server exhibits significant quality gaps across naming, parameter documentation, and schema completeness. Of 15 tools evaluated, only 3 have complete input schemas with proper type definitions and parameter descriptions. Tool names follow inconsistent conventions, some use verb-first patterns (register_server, delete_server) while others are generic (health_check, get_current_time). Descriptions are present but often lack actionable context or specificity about when to use a tool versus alternatives. The server mixes registry management tools (register_server, list_servers, search_servers) with utility tools (get_current_time, add_two_numbers, concatenate_strings) in a single server, violating single-responsibility principles. Critical parameter documentation is incomplete: register_server accepts a 'tools' array but provides no schema for what each tool object should contain. No output schemas are visible in the provided code, making it impossible for LLMs to understand return structures. Error handling guidance is absent, no recovery hints, retryability classification, or actionable error messages. Security considerations are not evident: no audit logging, no permission gating for destructive operations (delete_server), and no documentation of what credentials or secrets are required.
Tools (15)
add_two_numbersread only50/100
Add two numbers together
concatenate_stringsread only50/100
Concatenate two strings
delete_serverdestructiveauth50/100
Delete a registered MCP server from the registry
get_current_timeread only50/100
Get current time from timeapi.io API
get_registry_serverread only50/100
Get details about a specific server in the MCP Gateway Registry
No output schemas documented. LLMs cannot understand what fields to expect from tool responses, making it impossible to plan downstream operations or extract relevant data from results.
register_server accepts a 'tools' parameter (array) but provides no schema defining what each tool object should contain, no type info, required fields, or structure documented.
delete_server description is extremely brief (40 chars) and does not warn that this operation is destructive and irreversible. LLMs need explicit notice of side effects.
delete_server
Recommendations
Document complete output schemas for all 15 tools. Specify return type (object/array), required fields, field types, and any nested structures. Example: register_server should return {server_id: string, created_at: ISO8601}.
Add a 'tools' schema parameter to register_server. Define what each tool object must contain: {name: string, description: string, input_schema: object}. Use JSON Schema oneOf or $ref to enforce structure.
Rewrite delete_server description to explicitly state: 'Delete a registered MCP server from the registry. This action is irreversible and cannot be undone. Consider validating the server_id before calling this tool.'
Add error handling guidance to all tools. Document: (1) What errors can occur (e.g., 'Server not found', 'Duplicate name', 'Invalid URL'), (2) Which are retryable, (3) Recovery hints (e.g., 'Try search_servers() to find the correct server_id').
Rename overlapping tools or split into separate servers. Option A: Keep a single 'registry' server with canonical names (list, get, search, register, update, delete). Option B: Move utility tools (add_two_numbers, concatenate_strings, get_current_time, list_json) into a separate 'utilities' server.
Add bounds to pagination and numeric parameters. E.g., list_servers(skip: integer ≥0, limit: integer 1-100); list_json(count: integer 1-1000). Document defaults (e.g., 'Default limit is 20').
Constrain the timezone parameter in get_current_time. Either provide an enum of common timezones or a regex pattern (e.g., /^[A-Z][a-z]+/[A-Z][a-z_]+$/). Add a hint: 'Use IANA timezone names like America/New_York or Europe/London.'
Spec posture evidence
Inferred effective spec: <=2025-11-25.
Relies on Logging (deprecated) - log to stderr or use OpenTelemetry
Score history
Overall score trend
↓ 14 points across a rubric change (v1 → v2)
53/100
Scored
Grade
Overall
Spec posture
Rubric
2026-09-22
D
53
<=2025-11-25
v2
2026-03-09
C
67
-
v1
List all servers registered in the MCP Gateway Registry
list_serversread only50/100
List all registered MCP servers in the registry
register_serverwriteauth50/100
Register a new MCP server in the registry
search_registryread only50/100
Search the MCP Gateway Registry for servers by name or description
search_serversread only50/100
Search for MCP servers in the registry by name, description, or tools
update_serverwriteauth50/100
Update an existing registered MCP server
validate_serverread only50/100
Validate a registered MCP server's health and connectivity
No error handling or recovery guidance. Tools lack descriptions of what errors might occur, whether they are retryable, or what actions the LLM should take on failure.
Multiple tools perform registry operations (list_servers, list_registry_servers; search_servers, search_registry) creating naming ambiguity. LLMs may conflate or misselect between similar tools.
Utility tools (add_two_numbers, concatenate_strings, get_current_time, list_json) are mixed with domain-specific registry tools in a single server, violating single-responsibility principle and complicating agent discovery.
Parameter descriptions are often generic and lack constraint information. E.g., 'skip' and 'limit' parameters for list_servers lack min/max bounds or guidance on typical ranges.
list_json parameter 'count' lacks bounds (min/max). An LLM could pass count=1000000, causing resource exhaustion or timeout.
list_json
Implement server-side validation and permission checks. Add checks before delete_server and update_server to verify the calling agent has authorization. Return 403 Forbidden with a message like 'Insufficient permissions to modify server registry' if not authorized.
Add an audit log annotation to destructive operations. Log calls to delete_server and update_server with: caller ID, timestamp, old/new values, and outcome. Make logs queryable for compliance.
Separate utility tools into a distinct server. Create a 'mcp-utils' or 'arithmetic' server for add_two_numbers, concatenate_strings, list_json, and move get_current_time to a 'time' server. This allows agents to discover and use domain-specific registries cleanly.
Enhance register_server description with a multi-step use example: 'First validate the server is accessible using validate_server(), then register it with this tool. On success, the server is immediately queryable via get_server() and search_servers().'
Add idempotency guidance. State which operations are idempotent (register_server with duplicate name: error or upsert?) and which are not. This helps LLMs understand retry behavior.
Document what happens on partial failures. E.g., if search_servers finds 100 results but the response is truncated to 20, clarify: 'Results are paginated. Use skip and limit to fetch remaining items. Total matching servers: 100.'
Add resource relationship hints to responses. E.g., get_server should return fields that downstream tools accept: server_id (for update_server, delete_server), url (for validate_server), tools (for discovery).