Static source inference · medium confidence · detected: Logging
Deprecated protocol patterns detected
Summary
This project is a Spring AI backend template, not an MCP server. The codebase shows a ChatService with agent integration and a skill registry, but the tools (shell_exec, read_skill) are not registered as MCP protocol tools with proper schemas. Tool definitions are inferred from Java method signatures rather than explicitly declared via MCP tool registration. The code references Spring AI agent patterns and Alibaba's agent framework, but there is no evidence of MCP JSONSchema tool definitions, transport layer, or protocol compliance. Tool descriptions are minimal; parameter schemas are not visible in the provided source. Without explicit MCP tool registration and JSON schemas, these tools cannot be evaluated as production MCP tools.
Tools are not registered via MCP protocol. No evidence of JSONSchema tool definitions with type metadata, required fields, or enum constraints. Tool definitions appear to be Java method signatures, not MCP-compliant schemas.
Tool descriptions are extremely brief ('Execute shell commands via ShellTool2 agent hook', 'Read skill content from the skill registry'). Under 50 characters each, insufficient for LLM tool selection. No context on WHEN to use, WHAT it returns, or dependencies.
No input schemas visible in provided source. ChatService and SaaInMemorySkillRegistry Java code does not expose JSON schemas with parameter types, constraints, or descriptions. Parameter 'command' and 'skill_name' are inferred but not formally declared.
shell_execread_skill
Recommendations
Create explicit MCP tool definitions with complete JSONSchema. For shell_exec: include 'command' (string, max length, validation pattern), required=['command'], and output schema (exit_code: int, stdout: string, stderr: string). For read_skill: include 'skill_name' (string, enum of valid skills or pattern), required=['skill_name'], output schema (name: string, content: string, version: string).
Expand tool descriptions to 80 - 150 characters. For shell_exec: 'Execute a shell command on the server and return stdout, stderr, and exit code. WARNING: This tool modifies system state and has irreversible consequences. Always confirm with the user before executing destructive commands (rm, delete, drop database, etc.)'. For read_skill: 'Retrieve the full content of a registered skill, including its implementation, metadata, and version. Use this to understand available skill capabilities before invoking.'
Add per-parameter descriptions and type constraints. For shell_exec command parameter: 'The shell command to execute. Max 1000 characters. Supports bash/sh syntax. Avoid piping to /dev/null unless intentional; stderr is always captured. Example: ls -la /home/user'. For read_skill skill_name parameter: 'The name of the skill to retrieve. Must match an entry in the skill registry exactly (case-sensitive). Available skills can be listed via a discovery tool (not yet implemented).'
Implement shell_exec confirmation pattern: add optional 'dry_run' parameter (boolean, default false) and 'require_confirmation' (boolean, default true for dangerous commands). Return a confirmation token when dry_run=true or confirmation required, forcing a second call to confirm before actual execution.
Spec posture evidence
Inferred effective spec: <=2025-11-25.
Relies on Logging (deprecated) - log to stderr or use OpenTelemetry
shell_exec is marked DESTRUCTIVE but has no confirmation step, dry-run option, or permission gate. Tool description does not warn of irreversible consequences. Violates confirmation-request and permission-gate patterns.
No error handling or recovery guidance visible. No documentation of which errors are retryable, user-fixable, or fatal. No actionable error messages that tell the agent what to do next.
Tool definitions inferred from source rather than explicitly registered. No MCP server entry point, tool list endpoint, or transport layer visible. Cannot distinguish between Spring AI agent tools and MCP tools.
shell_execread_skill
Add error recovery guidance. For shell_exec: document 'If exit_code != 0, check stderr for specific error. Common issues: permission denied (try sudo), command not found (check PATH), timeout (increase timeout parameter). For read_skill: 'If skill not found, call list_skills() to see available skills, or check spelling/case.'
Implement tool annotations (readOnlyHint, destructiveHint, idempotentHint) in MCP tool definitions. Mark read_skill as readOnlyHint=true. Mark shell_exec as destructiveHint=true (unless validated as safe).
Add a skill registry discovery tool: list_skills() returning { name, version, description, parameters } for all registered skills. This enables agents to explore capabilities without hardcoding skill names.
Document output schemas explicitly. For shell_exec: { exit_code: number, stdout: string, stderr: string, execution_time_ms: number }. For read_skill: { name: string, content: string, version: string, last_modified: ISO8601 datetime }.
Implement input validation and sanitization inside tools. For shell_exec, reject known-dangerous patterns (rm -rf, >, |, etc.) unless explicitly whitelisted; return actionable error: 'Command contains dangerous pattern >. Piping to files is restricted. Use create_file tool instead.'
Add structured logging: log who called the tool (agent ID), parameters (sanitized), result, and timestamp. Include in audit trail for compliance.