MCP server integrated with EllyMUD runtime providing access to both static game data and live runtime state via HTTP. Supports tool-based gameplay commands, player management, game state inspection, and AI-driven interactions.
EllyMUD exposes 11 tools with basic descriptions and input schemas. However, the server has significant gaps in definition quality: output schemas are not documented, many parameter descriptions are minimal (under 50 chars), error handling guidance is absent, and security concerns around destructive operations are inadequately addressed. Tool naming is reasonable (verb_noun pattern mostly followed), but parameter validation rules, enum constraints, and recovery paths are largely missing. The schema definitions visible in the code are present but sparse, most tools declare input types but lack detailed parameter constraints, format specifications, or documented return structures. This is a functional but mediocre implementation typical of community-grade MCP servers.
Advance the game timer by specified number of ticks for testing. Only available in test mode or with API key authentication.
Directly log in as a user, bypassing authentication. Only available in test mode or with API key authentication.
Execute a game command as a virtual player session. Simulates player input and returns cleaned command output suitable for LLM consumption.
Retrieve current game state including all players, NPCs, rooms, and world state. Returns comprehensive snapshot of the MUD.
Get detailed information about a specific player including stats, inventory, skills, and location.
Get detailed description of a specific room including exits, NPCs, items, and connected players.
Output schemas are not documented for any tool. LLM cannot infer response structure, forcing blind composition or repeated calls to discover fields.
Destructive/sensitive operations (reset_game_state, load_test_snapshot, save_test_snapshot, set_player_stats, direct_login) lack tool-level confirmation or dry-run parameters. Auth gating is mentioned in descriptions but not enforced at the tool definition layer.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 58 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
Get list of all available in-game commands with their descriptions and usage.
Load a saved game state snapshot for testing. Only available in test mode or with API key authentication.
Reset the entire game state to initial conditions. Only available in test mode or with API key authentication. DESTRUCTIVE OPERATION.
Save current game state as a named snapshot for testing. Only available in test mode or with API key authentication.
Modify a player's stats for testing. Only available in test mode or with API key authentication.
Input parameter constraints are missing or minimal. Numeric parameters (ticks, stats) lack min/max ranges. String parameters (room_id, username, snapshot_name) lack format specifications, length limits, or allowed character sets. stats parameter in set_player_stats is type:object with no documented properties or enum constraints.
No error handling guidance. Tools do not document what errors can occur, whether they are retryable, or what the LLM should do next. e.g., get_player_info does not say 'Returns 404 if username not found; try list_commands() or search_players()'.
Sensitive/privileged tools (direct_login, set_player_stats, reset_game_state) do not declare required permissions or scopes. This blocks least-privilege agent configuration.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint). Clients and LLMs cannot infer tool safety from the definition alone. Per current MCP spec (2026-07-28), tools should include these hints.
Parameter descriptions are minimal (many under 50 chars) and lack actionable detail. e.g., session_id description is 'Optional session ID to maintain state across commands. If not provided, a new session is created.' but does not specify session lifetime, scope, or whether IDs must be UUIDs or can be arbitrary strings.
No pagination or result limits documented. get_game_state can return 'all players, NPCs, rooms' without documented limits, LLM may request full world state and blow context window. list_commands and similar discovery tools should specify max results and offer offset/limit params.