MCP server providing tools for banking operations including customer information retrieval, transaction history, account balance queries, and product search via RAG
The Banking MCP Server defines 4 tools with explicit schemas and descriptions in src/mcp/server.py. All tools follow verb_noun naming (get_*, search_*) which is correct. However, significant issues reduce quality: (1) API key is exposed as a tool parameter across all 4 tools, violating the secret-injection pattern, credentials must never be parameters; (2) Descriptions are minimal (10-27 chars) and lack context for LLM selection, they state WHAT but not WHEN or WHY to call; (3) No documented output schemas, LLMs cannot infer return structure or plan downstream calls; (4) Error handling is basic (status/error fields) with no recovery guidance; (5) No tool annotations (readOnlyHint, etc.) despite all being read-only operations. Positives: schemas are present and properly typed, all parameters have descriptions, naming is clear and unambiguous.
Get current account balance
Get customer information by ID
Get the last N transactions for a customer
Search for bank products using natural language query
API key exposed as tool parameter in ALL 4 tools (api_key in required schema properties). This violates secret-injection pattern, credentials must never be parameters. Agent traces log all parameters, leaking secrets into logs and prompt history.
Tool descriptions are too short (10-27 characters) and lack context. 'Get customer information by ID' does not explain WHEN to use this vs other lookup tools, or what fields are returned. LLMs cannot infer selection criteria from minimal descriptions.
No documented output schemas. The code returns structured JSON with status, customer, transactions, etc., but tool definitions do not document what fields LLMs should expect. This forces LLMs to guess at response structure and plan blind.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 48 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 38 | - | v1 |
No tool annotations. All 4 tools are read-only operations that should declare readOnlyHint: true. Without annotations, agents cannot determine which tools are safe to call speculatively vs which may modify state.
Error handling is basic (status/error dict) with no recovery guidance. When a customer is not found, the response is {'status': 'error', 'error': 'Customer X not found'}, no hint to search first or what to try next.
No pagination documented for get_last_transactions. While a 'limit' parameter exists (defaults to 5), there is no mention of total count, offset, or how to fetch older transactions. Large result sets could blow context window.