This server has critical gaps across all definition quality dimensions. Most tools lack meaningful parameter descriptions, output schemas are undocumented, error handling is minimal, and security concerns are unaddressed. The mysql_execute tool exposes raw SQL execution with dangerous write capabilities without confirmation or safeguards. Zentao tools have slightly better structure but still lack per-parameter descriptions and output schema documentation. No tool descriptions exceed the baseline quality threshold of production servers (194 chars average; these average ~60 chars). Parameter handling is unsafe, no input validation, no enum constraints, no format guidance.
Create a new user
Get database schema
根据Bug ID查询禅道Bug详情
根据需求ID查询禅道需求详情
根据用例ID查询禅道测试用例详情
Execute MySQL SQL statements (SELECT/INSERT/UPDATE/DELETE)
db_schema tool has an empty input schema with no properties defined and no description of what fields it returns. LLMs cannot plan to use this tool.
mysql_execute tool allows arbitrary SQL execution including DELETE/UPDATE/DROP with no input validation, no enum constraints on allowed statement types, and a 'confirm' parameter that is ignored in the handler code (line 'handleSQL(params.arguments)' does not check confirm flag). This violates the confirmation-request pattern and creates SQL injection risk.
create_user tool accepts 'name' and 'email' parameters but neither parameter has a description explaining format, constraints, or validation rules (e.g. is name a first+last name? Is email required to be unique?). LLMs cannot infer these constraints from names alone.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 43 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 41 | - | v1 |
All Zentao tools (get_zentao_story, get_zentao_bug, get_zentao_testcase) have descriptions in Chinese only, which may exclude non-Chinese-speaking developers and LLMs with weaker Chinese support. Descriptions also do not explain what fields are returned or how the results should be used in downstream calls.
No tool provides output schema documentation. Callers cannot predict the structure of responses from get_zentao_* tools or db_schema. This forces LLMs to execute and guess, risking failed downstream tool calls.
Error handling in mysql-mcp-server (index.js line 42-45) returns only a raw error message with isError=true. No guidance on whether the error is retryable, user-fixable, or fatal. No hints like 'Invalid column name, try db_schema() first to see available columns.'
Zentao client hardcodes login credentials in environment variables with no validation that they exist before use. If ZENTAO_BASE_URL, ZENTAO_USERNAME, or ZENTAO_PASSWORD are missing, the server exits but provides minimal guidance on what to configure. No error recovery for failed login attempts.
mysql_execute handler does not validate the 'sql' parameter against SQL injection or restrict to safe statement types. An LLM could be tricked into passing 'DROP TABLE users' and the tool would execute it without warning.