MCP Server untuk Sistem Informasi SMK (School Management Information System) — provides AI chatbot access to school database via MCP tools for attendance, payments, student profiles, and financial reports
The server defines 4 tools with reasonable structures, but has significant gaps in naming conventions, parameter descriptions, and output schema documentation. Tools use action verbs (rekap_*) that are not standard English (Indonesian naming), making them harder for LLMs trained primarily on English patterns to disambiguate. All tools have descriptions (10-150 chars baseline), but parameter descriptions are present and adequate. Input schemas use Zod validators with type constraints, but output schemas are not formally documented. Error handling exists but lacks recovery guidance. No tool annotations (readOnlyHint, idempotentHint, destructiveHint) are present, missing an opportunity to guide agent behavior. The server correctly uses MySQL backend and implements basic filtering/pagination, but the definition quality falls short of production baseline.
Menampilkan rekap kehadiran per kelas (dashboard wali kelas). Termasuk rata-rata kehadiran, total alpa, dan total sakit per kelas. Gunakan ketika user bertanya tentang performa kehadiran kelas atau laporan wali kelas.
Menampilkan rekap kehadiran/absensi setiap siswa dalam bulan dan tahun tertentu. Termasuk jumlah hadir, sakit, izin, alpa, dan persentase kehadiran. Gunakan tool ini ketika user bertanya tentang absensi, kehadiran, atau presensi siswa.
Menampilkan rekap tagihan dan pembayaran SPP per siswa. Termasuk jumlah tagihan, sisa tagihan, status (LUNAS/MENUNGGAK/BELUM LUNAS). Gunakan ketika user bertanya tentang SPP, tagihan, atau pembayaran siswa tertentu.
Menampilkan daftar siswa yang kehadirannya di bawah 75% (siswa rawan). Termasuk nomor WhatsApp orang tua untuk tindak lanjut. Gunakan ketika user bertanya tentang siswa bermasalah, sering bolos, atau kehadiran rendah.
Tool names use Indonesian action verbs ('rekap_*') instead of standard English verbs (get_, list_, search_). This violates the verb_noun naming convention that lets LLMs parse intent from names alone. 'rekap_kehadiran_siswa' should be 'get_student_attendance_summary' or 'list_student_attendance_by_month'. Indonesian names are opaque to models trained on English tool patterns.
No output schema is documented for any tool. The code calls 'formatResponse()' which returns text-wrapped JSON, but the LLM has no formal specification of what fields to expect (e.g., does 'persentase_kehadiran' always exist? is 'ringkasan' optional?). This forces LLMs to infer schema from examples, increasing parsing errors and token waste.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 48 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
No tool annotations (readOnlyHint, idempotentHint) are declared. All 4 tools are read-only queries (no side effects), but the server never signals this. Agents cannot distinguish safe-to-retry tools from destructive ones without this metadata.
Error responses are minimal ('Gagal mengambil data kehadiran: {error.message}'). They do not guide the LLM on what to do next, what was invalid, or whether to retry. Per the recovery-guide pattern, errors should suggest alternatives (e.g., 'If month/year is invalid, try calling with current date' or 'Check that kelas filter matches available classes').
'siswa_rawan_kehadiran' returns WhatsApp numbers for parent follow-up, but no privacy/data protection note is documented. This is sensitive PII that should be access-controlled and logged for compliance. No permission gate or audit trail is declared.
The 'status' enum in 'rekap_tagihan_spp' uses lowercase values ('lunas', 'belum_lunas', 'menunggak') but the query logic and response likely use different casing or formats. No validation ensures the LLM passes exactly the right case. This invites silent failures or SQL injection if the enum is not strictly enforced.