Skill-powered AI agents implementing the Agent Skills specification with pydantic-ai
This server has critical definition quality gaps. Only 2 of 4 tools have non-trivial descriptions. Parameter descriptions are completely absent (all marked null in schema). Tools lack proper composition, 'run_script' is a generic execution wrapper that violates single-responsibility principles. No error handling guidance visible. No output schemas documented. This server would not pass code review for production use.
Add two numbers.
Greet someone by name.
Read a resource file from the skill directory.
Execute a script from the skill's scripts/ directory.
All parameter descriptions are null. The schema shows {'a': {'type': 'integer', 'description': null}, 'b': {'type': 'integer', 'description': null}} for 'add', and similar patterns for 'greet', 'read_resource', and 'run_script'. LLMs cannot infer parameter meaning without descriptions.
'run_script' is a generic execution tool that accepts arbitrary scripts and arguments. This violates single-responsibility principles and is a security risk. It should either be removed or replaced with domain-specific tools (e.g., 'execute_analysis_script', 'execute_extraction_script') with fixed allowed scripts.
No output schemas are documented for any tool. Tool descriptions do not state what fields are returned or what structure the response has. LLMs cannot plan downstream operations without knowing the shape of returned data.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 47 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 26 | - | v1 |
'add' and 'greet' are trivial fixtures with minimal descriptions ('Add two numbers', 'Greet someone by name'). These are under 50 characters and lack context for when/why an LLM would call them. Descriptions should explain use cases and prerequisites.
'run_script' accepts 'script' and 'arguments' as freeform strings. No validation or whitelist is visible. This invites command injection and path traversal attacks. The description does not explain what scripts are available, how paths must be formatted, or what security constraints apply.
Parameter 'path' in 'read_resource' has a description ('Relative path to the resource file') but is marked READ_ONLY risk. No constraint on allowed directories (no mention of staying within skill directory). Vulnerable to path traversal (../../../etc/passwd).