Provides access to Moodle courses, content, calendar events, resource download, and class schedule.
MUSTER MCP has 7 tools with clear verb-based naming (get_, download_, open_) and explicit JSON Schema definitions visible in main.py. However, schema quality is uneven: most tools have minimal or empty parameter sets, and critical input/output documentation is missing. Tool descriptions are present but generic (10-50 chars for several tools). Error handling is basic, functions return error dicts inline without actionable recovery guidance. No tool annotations (readOnlyHint, destructiveHint, idempotentHint) are present. Composition is weak: several tools are read-only utility functions (get_current_time, get_class_schedule) that don't chain well. Output schemas are completely undocumented, LLMs cannot plan downstream calls without knowing what fields to expect. This is a C-grade server: functional baseline met, but multiple significant gaps that would require refinement before production deployment.
Download Moodle resource file(s) (PPT, PDF, etc.) from a URL. Supports saving to a custom local directory.
Get all available courses and URLs from Moodle.
Get class schedule in this week; pass null for full week, or date (YYYY-MM-DD) to filter. If you need multiple days, pass null once instead of multiple calls.
Get all assignments/resources for a course by exact name (call get_all_courses first).
Get current local datetime as YYYY-MM-DD HH:MM:SS.
Get upcoming events and deadlines from Moodle calendar.
No output schemas documented for any tool. LLMs cannot plan downstream calls or extract required fields without reverse-engineering from code.
Multiple tool descriptions are under 20 characters (get_pending_events: 7 words; get_current_time: 5 words).
No tool annotations (readOnlyHint, destructiveHint, idempotentHint) present. download_resource and open_URL_with_authorization have side effects (write to disk, open browser) but are not marked as such. Agents cannot distinguish safe from risky operations.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-21 | D | 57 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 53 | - | v1 |
Open a URL in a new authorized browser window after Moodle login (show to user).
Error responses are inline dicts without actionable recovery guidance. E.g. 'Failed to get courses: {str(e)}' returns raw exception text. Per pattern:recovery-guide, errors should guide the LLM: what can be retried? what was the root cause? what should the user do?
download_resource accepts download_path as a user-provided string without path traversal validation. Tool is vulnerable to malicious path injection (e.g. '../../' escaping the intended folder). Per pattern:tool-gateway, all agent input must be sanitized.
open_URL_with_authorization opens a persistent browser window (Selenium driver). No timeout, no closure mechanism, no permission gate documented. Per pattern:permission-gate, sensitive operations (opening authenticated sessions) must verify authorization and audit. Side effects are not reversible.
No pagination or result limiting documented for list-returning tools (get_all_courses, get_course_content, get_pending_events). If a Moodle instance has hundreds of courses, responses could exhaust context windows. Per pattern:paginated-result, large-list tools must offer pagination.
Tool descriptions lack context on when to use each tool and dependencies between them. E.g., get_course_content doc says 'call get_all_courses first' only as a note, not integrated into the description text. Per pattern:tool-description, dependencies should be explicit.