MCP server for Kubernetes cluster discovery, network topology scanning, ArgoCD synchronization, and Git repository management for 5G NFR (Network Function Repository) configuration.
The server has 5 tools with mixed quality. Three tools (cluster_scan_topology, git_clone_repos, git_commit_push) have moderately detailed descriptions and structured schemas. However, critical issues undermine the overall score: (1) tool naming lacks action verbs or is generic (echo, cluster_scan_topology uses underscore-separated nouns rather than verb_noun pattern); (2) most parameter descriptions are minimal or omitted entirely; (3) output schemas are not documented in the visible code; (4) error handling is absent or unguided; (5) no security considerations are evident (git_commit_push accepts username/password as parameters, violating secret-injection pattern). The codebase shows tool registration via MCPTool struct with Name and Description, but actual parameter schema validation and output documentation are not visible. This is a domain-specific toolkit for Kubernetes/GitOps that follows basic MCP structure but lacks production-grade polish expected for A/B tier tools.
Trigger ArgoCD Application sync by patching Application.operation.sync (works without argocd CLI).
Discover clusters with their Git repositories and network topology. Use for Phase 1 discovery: find target clusters (core/edge/regional), get current IP/CIDR allocations, pod/service CIDRs, and associated git URLs. Example: {"clusterName":"regional", "includeTopology":true} returns cluster info with networkInterfaces (name, IPs, CIDRs), podCidrs, serviceCidrs, and gitURL.
Echoes a message back to the user.
Clone git repositories to local workdirs. Reuses existing valid repos or clones fresh. Use before scanning/patching manifests. Returns workdir paths for each repo. Example: {"repos":[{"name":"cucp","url":"http://gitea.com/nephio/5g-cucp.git","branch":"main"}], "baseDir":"/tmp/work"}.
Stage, commit (if changes), and push many repos. Supports HTTP auth using temporary GIT_ASKPASS.
Credentials exposed as tool parameters: git_commit_push accepts 'username' and 'password' as input parameters. This violates the secret-injection pattern, credentials will be logged in agent traces, prompt history, and error messages.
No output schemas documented. Tools return structured objects (ArgoCDSyncAppResult, inferred workdir paths, etc.) but these are not declared in tool definitions. LLMs cannot anticipate what fields to extract, forcing them to infer structure from descriptions alone.
Parameter descriptions are minimal or absent. Many parameters (e.g., 'namespace', 'ref', 'depth', 'concurrency') lack meaningful descriptions explaining their purpose or valid ranges. Baseline is 72 chars per parameter description; most here are <20 chars.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 54 | 2025-06-18+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
Tool naming does not consistently follow verb_noun pattern. 'echo', 'cluster_scan_topology', 'git_clone_repos' use nouns or underscore-separated compound names. Standard pattern is verb_noun: 'scan_clusters', 'clone_repos', 'sync_argocd_app'.
No error handling guidance. Tools lack descriptions of what errors they return, when they are retryable, and what the agent should do next. E.g., 'git_commit_push' may fail on auth errors, network errors, or merge conflicts, but there is no guidance.
Compound action tool: 'git_commit_push' performs two distinct operations (commit and push). Per single-responsibility pattern, these should be separate tools ('git_commit' and 'git_push') so agents can compose them as needed.
No input validation constraints documented. Parameters like 'concurrency' (git tools) lack min/max bounds; 'namespace' lacks format guidance; boolean flags like 'prune' and 'pull' lack usage examples. LLMs cannot infer valid ranges.
Missing permission/scope declarations. Tools like 'argocd_sync_app' (write) and 'git_commit_push' (write) do not declare what permissions they require. No audit trail guidance for who called what.