MCP server for C2SAgent that manages tools and integrates with LLM agents for task execution, time series forecasting, multi-agent coordination, and streaming responses.
C2SAgent MCP Server exhibits severe definition quality gaps across nearly all 17 tools. Most tools have vague, generic descriptions that fail to communicate intent or prerequisites. Input schemas are poorly documented, many parameters lack type information or descriptions. Tool names are inconsistent: some use action verbs (call_tool, list_tools, do_mcp_create) while others are prefixed with 'do_' (do_mcp_delete, do_tool_list) without semantic clarity. No output schemas are documented. Error handling is absent, no recovery guidance or actionable error messages. The server conflates operational tools (MCP server management) with application tools (A2A agent queries, session management) in a single tool set, violating single-responsibility principles. Tools like 'call_tool' and 'stream_ask_a2a' expose dangerous flexibility without guardrails. Credentials (jct, sessdata) appear as parameters in do_media_update, violating secret-injection patterns. No tool declares permissions or destructive intent clearly. This server would not pass review by a production tool engineer.
Processes an MCP agent query with streaming response. Integrates with MCP servers to handle tool invocations and returns streamed results.
Submits a question to an A2A agent and returns the agent's response. Manages conversation sessions stored in MongoDB and routes queries to configured agents.
Executes an API tool by name with provided arguments. Searches for the tool, retrieves its handler configuration (URL, method, authorization), and makes the HTTP request with the specified parameters.
Creates a new conversation session for the authenticated user with an initial system message.
Deletes a conversation session by ID for the authenticated user.
Retrieves all conversation sessions for the current authenticated user from MongoDB.
Credentials exposed as tool parameters (jct, sessdata in do_media_update). Agent call traces log all parameters; secrets will leak into logs and prompt history.
Destructive tools (do_mcp_delete, do_delete_session) lack confirmation/dry-run steps. Agents can delete data irreversibly without user approval.
Tool names are inconsistent and vague: mixing 'do_' prefix (do_mcp_create, do_tool_list) with standard patterns (call_tool, list_tools, ask_agent). Cryptic abbreviations (corr_tool, discorr_tool) prevent LLM intent inference.
Output schemas are missing for all 17 tools. LLMs cannot plan downstream calls or extract required fields (IDs, references) for chaining.
Inferred effective spec: 2026-07-28+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 46 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
Loads a specific conversation session by ID, including all messages and history.
Associates a tool with an MCP server by adding the tool definition to the server's tool list.
Creates a new MCP server record with a given name for the current authenticated user.
Deletes an MCP server record by ID for the current authenticated user.
Removes a tool association from an MCP server by deleting the tool from the server's tool list.
Returns a list of all MCP servers associated with the current authenticated user.
Retrieves a list of all media resources associated with the authenticated user.
Updates media credentials/metadata (name, jct, sessdata) for an authenticated user.
Returns a list of all tools associated with a specific MCP server.
Returns a list of all tools available for a specific MCP server. Tools are retrieved from the database based on the server name/group extracted from the request context.
Submits a question to an A2A agent with streaming response. Supports time series forecasting, multi-agent coordination, thought processes, and file uploads. Returns Server-Sent Events stream.
Input parameters lack type and validation constraints. E.g., 'name' (string) in do_mcp_create has no length, pattern, or forbidden character constraints. 'session_id' format is undocumented. Parameters accepting IDs (mcp_server_id, agent_id) have no range validation.
Descriptions are generic or missing context. Many are single short sentences (< 50 chars) that do not explain prerequisites, side effects, or when to use the tool over alternatives (e.g., ask_agent vs stream_ask_a2a).
call_tool and stream_ask_a2a accept untyped 'arguments' or feature flags (isTimeSeries, isAgent, etc.) without documenting valid combinations, constraints, or side effects. call_tool makes arbitrary HTTP requests with no timeout, rate limit, or error recovery guidance.
No error handling documented. Tools do not return actionable recovery guidance. E.g., 'User not found. Try do_list_session() to find valid sessions.' Agents cannot self-correct on failures.
Tool set conflates operational concerns (MCP server CRUD: do_mcp_create, do_mcp_delete, do_tool_list) with application concerns (session management: do_create_session, do_load_session) and agent queries (ask_agent, stream_ask_a2a). This violates single-responsibility and makes tool selection ambiguous.
No permission declarations. Tools do not state what scopes they require (read:agent, write:mcp, delete:session). Agents cannot be configured with least-privilege access.
stream_ask_a2a combines multiple features (time series, multi-agent, thoughts, doc analysis) into one tool with feature flags. This violates single-responsibility and makes it hard for LLMs to understand when to use it or which flags are relevant.
No pagination or result-limit documentation. Tools like list_tools, do_list_session, do_media_list do not state if they cap results or require pagination parameters. Large result sets can bloat the LLM context window.