Spring Boot OAuth2 authorization server with integrated MCP server support and Oracle database migration tools (DDL/DCL script generation and PostgreSQL to Oracle data migration)
This server has three tools, but only two are fully defined with visible schemas and descriptions (generateScripts, migrate). The two primary Oracle tools have acceptable descriptions (200+ chars), but the input parameters lack individual descriptions despite being complex objects. Parameter descriptions are critical for LLM reasoning, 'source' and 'destination' are vague labels without field-level guidance. Neither tool documents output schemas. Descriptions do not clarify when migrations are retryable or if errors are recoverable. generateScripts references 'legacy mode' and 'map-based mode' but does not explain which mode to use or how they differ operationally. migrate accepts credentials as parameters (source.username, source.password, destination.username, destination.password), a critical security violation: credentials should never be tool parameters. Overall, the server falls in the 'poor' range (50 - 59): acceptable naming, present-but-vague descriptions, incomplete parameter documentation, missing output schemas, and security issues with credential exposure.
Tools (3)
generateScriptsread onlyauth50/100
Analyzes a PostgreSQL database schema and generates a formatted Oracle SQL file containing DDL and DCL scripts. Generated scripts include CREATE SEQUENCE statements, CREATE TABLE statements, CREATE INDEX statements, ALTER TABLE for foreign key constraints, and role-based GRANT statements. Supports legacy mode (single targetSchema) and map-based mode (split tables into multiple Oracle schemas).
migratewriteauth50/100
Migrates data from PostgreSQL to Oracle database. Performs async data migration with progress tracking, batched inserts, multi-threaded processing, and support for table schema mapping.
weatherread only26/100
Tool from WeatherService registered via MCP ToolCallbackProvider for weather-related queries
Rename tools to action-verb format: 'generate_scripts', 'migrate_data', 'get_weather'. Use snake_case for consistency with MCP naming conventions.
Remove all credentials from tool parameters. Instead: (1) Configure PostgreSQL and Oracle connection pools in application.properties with environment variable injection. (2) Add parameters for connection names or aliases (e.g., 'source_connection_alias: "prod_postgres"', 'destination_connection_alias: "oracle_prod"'). (3) Resolve aliases to credentials server-side.
Add per-parameter descriptions to input schemas. For generateScripts, document each field: 'source: PostgreSQL connection config { jdbcUrl (required), username (required), password (required, inject via env), schema (required), driverClassName (optional, defaults to org.postgresql.Driver) }', 'targetSchema: Oracle schema name (2-30 uppercase alphanumeric + underscore)', 'tableSchemaMap: routing map {...}', 'editRoleName: custom edit role (optional, defaults to {targetSchema}_EDITOR)', etc.
Document output schemas: generateScripts should clarify 'Returns a single string containing complete Oracle DDL/DCL script. Script is production-ready and can be executed directly.' migrate should document 'Returns { migration_id: UUID, status: "in_progress"|"completed"|"failed", rows_migrated: integer, rows_failed: integer, completion_time_ms: integer, error_details: string (if status=failed) }'.
Add error handling section to each tool description: 'Errors: Connection failure (retryable after 5s), invalid schema name (user-fixable, suggest available schemas), permission denied (escalate to DBA). If migration partially fails, run migrate again with same parameters, idempotent inserts skip duplicates.'
Credentials must not be stored or logged; no mention of TLS or encryption
generateScriptsmigrate
Clarify generateScripts legacy vs map-based modes with decision tree: 'If all tables go to one schema, use targetSchema (legacy). If tables split across multiple schemas, use tableSchemaMap (map-based). Cannot use both simultaneously.'
Implement server-side secret management: Use Spring Cloud Config or HashiCorp Vault to store PostgreSQL/Oracle credentials. Reference them by alias in tool parameters. Log only the alias, never the password.
Add an output schema for the weather tool. Extract WeatherService callback and create explicit tool definition with input schema (e.g., 'location: string (city or coords)', 'units: enum ["celsius", "fahrenheit"]') and output schema (e.g., '{ temperature, humidity, conditions, forecast[] }').
Consider splitting migrate into two tools if applicable: migrate_schema (just DDL/DCL from generateScripts) and migrate_data (data movement). This allows agents to validate schema before starting data migration.
Add idempotency guarantees: 'migrate tool is idempotent, calling it multiple times with the same source and destination produces the same result. Duplicate rows are skipped via unique constraints. Safe to retry on network failures.' This enables confident agent replay on ambiguous errors.