MCP server providing tools for querying and interacting with OCI (Open Container Initiative) image registries
ocireg-mcp demonstrates solid definition quality with clear naming conventions, complete parameter descriptions, and proper schema registration via the mcp-go framework. All 6 tools follow verb_noun naming patterns (get_*, list_). Descriptions are comprehensive and contextual. Tool annotations (readOnlyHint, destructiveHint, idempotentHint) are properly applied. However, output schemas for 2 of 6 tools are not fully visible in the source, and error handling guidance is minimal. Per-tool scores average 72, driven by strong naming/descriptions but incomplete schema visibility.
Get the config for an OCI image
Get information about an OCI image
Get the manifest for an OCI image
Fetch the content of a specific referrer artifact. Use list_referrers first to discover artifacts and their digests. Returns content as an embedded resource with proper MIME type. For cosign attestations (DSSE envelopes), automatically decodes the base64 payload unless decode_payload is false.
List OCI artifacts (SBOMs, signatures, provenance, VEX) attached to an image via the OCI Referrers API. Returns descriptors with artifact type, digest, size, and annotations. Use this to discover what attestations exist before fetching their content with get_referrer_content.
List tags for a repository with pagination support
Output schemas for get_image_manifest and get_image_config not visible in provided source; only get_image_info, list_tags, and list_referrers show mcp.WithOutputSchema[...] calls. This caps schema scores at 50 for those tools since pattern requires documented return types.
Error handling guidance is absent from tool descriptions and source. No recovery paths documented (e.g., 'If image not found, try list_tags to verify repository exists'). Tools rely on caller to infer remediation.
get_referrer_content has optional boolean decode_payload and optional string content_type parameters without constraints, but no guidance on what happens if decode_payload=false when payload is not a DSSE envelope, or what content_type values are valid beyond the enum hint.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 74 | 2025-06-18+ | v2 |
| 2026-03-09 | D | 52 | - | v1 |
list_tags accepts a numeric 'limit' parameter with max 1000, but no minimum is documented. The description states 'default: 100, max: 1000' but omits minimum (likely 1). Baselines show numeric params should have explicit min/max ranges.