The server defines 3 tools with basic input schemas and descriptions. However, critical gaps prevent higher scoring: (1) No output schemas are documented for any tool, LLMs cannot know what fields to expect in responses. (2) Parameter descriptions exist but are minimal (10-30 chars), below the 72-char baseline for production tools. (3) Tool names are adequately action-oriented (show_*, execute_*), but descriptions lack WHEN/WHY guidance and don't explain error recovery. (4) No error handling guidance, execute_query silently returns error dicts instead of actionable error messages. (5) Input validation is weak: execute_query checks for 'SELECT' prefix but doesn't prevent injection or provide recovery hints. (6) No pagination support on show_tables despite potentially returning many rows. (7) No timeout or rate-limit documentation in descriptions. Most production tools at this maturity level score 45-55; this server is near that median.
Run a SELECT query against Doris with timeout protection.
List all databases in the Doris instance.
List all tables in the specified database.
No output schemas documented for any tool. Agents cannot know what fields to expect in responses.
Parameter descriptions are 24-58 chars; baseline is 72 chars. Descriptions lack detail on valid ranges, formats, and constraints.
execute_query silently validates input (SELECT-only check) without documenting this constraint in the schema or description. Agents cannot know why non-SELECT queries fail.
No pagination or result-limit mechanism on show_tables. Large database schemas could exhaust context window.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-21 | F | 49 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 11 | - | v1 |
Error messages returned by execute_query (e.g., 'Queries taking longer than 30 seconds are currently not supported') are undocumented. No guidance on how agents should respond to timeouts or validation errors.
show_databases and show_tables descriptions do not explain when/why to call them vs similar tools. No dependency hints (e.g., 'Call show_databases first to see available schemas').
No input validation on 'database' parameter (show_tables) or 'query' parameter (execute_query) to prevent SQL injection or path traversal. Backtick escaping in code is minimal mitigation.