Java 内存马检测和清理工具的 MCP 服务器 - Memory Shell Detector MCP Server
The server has 2 tools with substantial parameter schemas, but critical quality issues significantly impact usability. Tool descriptions are present and reasonably detailed (194-250 chars each), meeting baseline length expectations. However, both tools exhibit major naming and parameter clarity problems: (1) 'execute_command' is a generic verb without specific action context, conflicting with the LLM naming pattern; (2) parameter documentation lacks constraints (e.g., regex patterns for ssh_host, enum values for port ranges); (3) no output schemas are documented despite complex return structures; (4) security-critical parameters (ssh_password) are exposed as input fields rather than injected; (5) error handling is minimal, no recovery guidance, no per-error classification. The tool composition also raises concerns: execute_command and download_detector_tools overlap in SSH capability, creating decision ambiguity for LLMs. Schema quality is moderate, JSON Schema types are present for all parameters, but descriptions are inconsistent (some detailed, others minimal). The server references tools not visible in source (list_java_processes, scan_process, view_class_code, remove_memory_shell, export_report) in the MCP instructions; these are inferred rather than explicitly registered, capping their scores at 50.
下载 Java 内存马检测工具包(detector-agent.jar 和 detector-cli.jar) 此工具会下载两个核心 jar 包: - detector-agent-1.0.0-SNAPSHOT.jar: Java Agent,用于注入目标 JVM 进程 - memory-shell-detector-cli.jar: 命令行工具,提供扫描、反编译、移除等功能 这是使用内存马检测功能的前置步骤,下载完成后才能执行后续的扫描和分析操作。
执行系统命令(本地或通过 SSH 远程执行) 这是一个通用的命令执行工具,可用于: - 检查 Java 环境是否正常(java -version) - 查看系统进程状态(ps aux) - 执行其他辅助命令 注意:内存马检测的核心功能请使用专用工具(list_java_processes、scan_process 等), 此工具仅用于辅助操作。
Credentials (ssh_password, potentially ssh_key_path) exposed as plaintext tool parameters. All SSH authentication should use server-side secret injection via environment variables or secure vaults. Secrets in tool parameters leak into agent logs and prompt history.
Output schemas not documented for either tool. Callers cannot infer what fields to extract or how to chain results to downstream tools. For execute_command: is stdout always a string? What about partial results on timeout? For download_detector_tools: does it return JAR paths, file sizes, checksums?
No error classification or recovery guidance. Functions return {success: false, stderr: <message>} but do not categorize errors as retryable, user-fixable, or fatal. LLMs cannot determine next action: should they retry? Ask for input? Abort?
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 51 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
Parameter descriptions lack constraints, ranges, and examples. ssh_host has no regex or format. ssh_port defaults to 22 but no enum constrains valid values. timeout defaults to 300 but no min/max specified. Tools in description reference list_java_processes, scan_process, view_class_code, remove_memory_shell, export_report, none are visible in source code, suggesting inferred/missing tool definitions.
Naming: 'execute_command' is generic and does not follow verb_noun pattern with specificity. 'execute_command' could mean HTTP GET, SSH exec, local shell, or database query. Better: 'run_local_command', 'execute_remote_command', or split into two specialized tools. Similarly, 'download_detector_tools' is compound, 'download_' + 'tools', and vague about what tools.
SSH parameters repeated across both tools (ssh_host, ssh_username, ssh_password, ssh_key_path, ssh_port). No documented relationship between these fields, when is password required vs. key_path? Are both optional? This creates ambiguity for LLM input selection.
Tool composition concern: both execute_command and download_detector_tools support SSH. download_detector_tools could internally use execute_command for the download, but instead duplicates SSH logic. This creates decision paralysis for LLMs: which tool to call first?
MCP instructions reference 5 tools (list_java_processes, scan_process, view_class_code, remove_memory_shell, export_report) that are not visible in the source code provided. If they do NOT exist, the server is significantly incomplete.