MCP bridge for Gemini CLI and handy system/web tools
The server defines 6 tools with explicit FastMCP @mcp.tool() registration and visible input schemas. Tool names follow verb-noun conventions (gemini_prompt, gemini_version, gemini_mcp_list, gemini_mcp_add, gemini_mcp_remove, gemini_web_fetch). However, descriptions are present but minimal (18 - 80 chars, averaging ~45 chars), falling below the 194-char production baseline. All tools have input schemas with type definitions and descriptions for parameters, meeting the schema baseline. Output is uniformly returned as JSON strings rather than structured objects, limiting downstream composition. Error handling is basic (RuntimeError on non-zero exit, but no recovery guidance or actionable messages for LLMs). Tool composition is reasonable, each has a single responsibility, but the return format (always JSON-stringified) makes it hard for agents to extract and chain results without re-parsing. Security: credentials are passed as parameters (see gemini_mcp_add with headers, env_vars) rather than server-side injection, violating pattern:secret-injection. No permission gates, scope declarations, or audit trails. SSRF mitigation present (_is_private_url) is a positive.
Add an MCP server via gemini CLI (gemini mcp add ...). transport: stdio|http|sse; for stdio pass executable, for http/sse pass URL. headers are only valid for http/sse. Returns CLI stdout.
List MCP servers configured in gemini CLI (gemini mcp list). Scope: user|project.
Remove an MCP server from gemini CLI (gemini mcp remove <name>).
Run local `gemini` CLI non-interactively; return structured JSON.
Return installed gemini CLI version (gemini --version) as JSON.
Fetch and analyze web content via gemini CLI with URL validation.
Tool descriptions are too short (18 - 80 chars, avg 45 chars vs. production baseline of 194 chars). Descriptions lack context on WHEN to use each tool, making LLM selection ambiguous.
Credentials and secrets passed as parameters: gemini_mcp_add accepts env_vars (dict) and headers (dict) directly, allowing callers to inject secrets. These appear in logs and LLM traces. Violates pattern:secret-injection.
All tool outputs returned as JSON-stringified strings (via _run_gemini_and_format_output), not structured objects. Agents must parse JSON inside JSON, increasing token cost and error likelihood. Violates pattern:response-shaper.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 27 | - | v1 |
Error handling is minimal. RuntimeError on failure, but no recovery guidance. E.g., if gemini CLI not found, LLM sees 'command exit 1' with no suggestion to install gemini. Violates pattern:recovery-guide.
gemini_mcp_add description does not clarify which parameters are mutually exclusive (e.g., command_or_url vs. others for different transport types). Agents may pass invalid combinations.
No permission gates, scope declarations, or audit trails. Destructive tool (gemini_mcp_remove) is not flagged as such and requires no confirmation. Violates pattern:permission-gate and pattern:confirmation-request.
Parameter 'timeout_s' is optional and unbounded. No minimum/maximum declared. Agents could pass negative or extreme values. Violates pattern:constrained-input.