Chicory is a platform with multiple services including agent-service, backend-api, db-mcp-server, inference-worker, and training-worker. The db-mcp-server is an MCP server that provides database connectivity tools for Databricks, Snowflake, Google BigQuery, and PostgreSQL.
Chicory's db-mcp-server exposes 4 SQL query tools across different warehouse platforms. While tool names follow the verb_noun pattern (query_databricks, query_snowflake, query_bigquery, query_postgresql), the implementation has critical gaps in schema completeness, parameter descriptions, output documentation, and error handling. All four tools share identical structural deficiencies. Input schemas are present but parameters lack actionable descriptions beyond names. No output schemas are documented, preventing agents from understanding what fields to expect or how to chain results. Error handling is absent, no guidance on retryability, user-fixable errors, or recovery paths. The tools accept raw connection strings and SQL directly, creating injection risks without visible input validation or sanitization layers.
Execute SQL query against Google BigQuery
Execute SQL query against Databricks
Execute SQL query against PostgreSQL database
Execute SQL query against Snowflake
No output schemas documented. Agents cannot infer result structure, required fields for downstream chaining, or pagination support. All four tools lack return type documentation.
Parameter descriptions are minimal (tool names only, <20 chars). 'sql' needs format/constraint guidance (length limits, SQL dialect specifics). Warehouse/connection_id parameters lack contextual help (how to find valid values, format expectations).
Direct SQL parameter invites SQL injection. No visible input sanitization, parameterized query enforcement, or validation documented. Agents and users could craft malicious SQL. Tool descriptions do not warn of this risk or guide safe usage.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 37 | 2026-07-28+ | v2 |
| 2026-03-09 | C | 62 | - | v1 |
Connection strings are exposed as parameters (query_postgresql). Credentials should be injected server-side via environment variables or vault, not passed by agents. This violates secret-injection pattern.
Tool descriptions lack WHEN/WHY context. Description 'Execute SQL query against Databricks' does not explain use cases, when to call this vs a discovery tool, what results mean, or whether results are paginated.
No error handling guidance. No indication of retryability, timeout behavior, malformed-SQL handling, authentication failure recovery, or rate limiting. Agents have no way to recover from failures.
No pagination or result limits documented. Tools may return thousands of rows, exhausting context windows. No mention of limit, offset, or cursor parameters. Baseline pattern expects pagination support for list-returning tools.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint). While all four tools are marked READ_ONLY in metadata, this is not conveyed via MCP toolAnnotations in the schema. Agents cannot verify safety without reading external docs.