An experimental sandbox and a lab to explore mcp hosts, mcp clients, and mcp servers. Perform attacks against mcp servers and abuse LLMs
Two tools with minimal but present schemas and descriptions. Both tools accept a single 'url' parameter with basic type and description. Descriptions are present but generic (18-29 chars each, below the 50-200 char LLM-optimized baseline). No input validation rules documented in descriptions. No output schemas visible. No error guidance. Tool names follow verb_noun pattern (describe_*, summarize_*) but lack specificity about expected behavior. No security/permission documentation. Error handling exists in implementation but is not surfaced to the LLM in tool definitions.
provide the description of a github repository
summarizes a github repository
Descriptions are below LLM-optimized baseline (18-29 chars vs 50-200 target). 'provide the description of a github repository' and 'summarizes a github repository' lack context about when to use each tool, what they return, and how they differ.
Output schemas are not documented. LLM cannot infer what fields are returned, whether results are paginated, or what structure to expect. Both tools return strings, but descriptions do not explain this.
Parameter 'url' lacks validation rules in description. No statement of required format (must be HTTPS GitHub URL), no examples of invalid inputs, no guidance on what happens if URL is malformed or private repo.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 46 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 33 | - | v1 |
No distinction between the two tools in descriptions. Both claim to operate on 'a github repository' but one extracts description metadata, the other summarizes README content via LLM. LLMs will struggle to choose the right tool.
Error handling logic exists in Python code (HTTP status checks, parsing failures) but is not conveyed in tool descriptions. LLM cannot plan error recovery or know whether to retry.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint). Both tools are read-only but this is not explicitly signaled in the schema.
Hardcoded external service dependencies (Ollama at 'http://windows:11434'). If service is down, summarize_github_repo fails silently. No fallback or graceful degradation documented.