MCP server for integrating web crawling and RAG into AI agents and AI coding assistants
This MCP server has critical definition quality issues that prevent confident production use. Of the 6 tools, all have descriptions, but 5 of 6 lack complete input schemas visible in the provided source code. Tool naming follows basic patterns (verb_noun for detect_hallucinations, batch_detect, analyze_script, validate_script, generate_comprehensive_report, analyze_python_file), but parameter schemas are either missing or incomplete. The server appears to be a domain-specific tool for detecting AI hallucinations in Python scripts using Neo4j knowledge graphs, but the tool definitions are not sufficiently documented for LLM-safe invocation. Key baseline violations: (1) 5 tools have no visible input schema definitions, cannot verify parameter types, descriptions, or constraints. (2) Tool descriptions are domain-specific but lack WHEN-to-use guidance and error recovery instructions. (3) Output schemas are completely undocumented, LLMs cannot know what fields to expect. (4) No error handling guidance or recovery paths. (5) Security implications of Neo4j credentials not addressed in tool definitions.
Extract Python file structure for direct Neo4j insertion including classes, methods, functions, and imports
Analyze a Python script using AST to extract imports, class instantiations, method calls, function calls, and attribute accesses
Detect hallucinations in multiple scripts
Main detection function that analyzes a script and generates reports for AI coding assistant hallucinations
Generate a comprehensive report in JSON format about detected hallucinations
Validate entire script analysis against Neo4j knowledge graph
5 of 6 tools have no visible input schema definitions in source code. Cannot verify parameter types, descriptions, ranges, or enums.
No output schemas documented for any tool. LLMs cannot know what fields to expect.
No descriptions explain what the tools return or how they compose.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 39 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 25 | - | v1 |
Neo4j credentials (neo4j_uri, neo4j_user, neo4j_password) must not be exposed as tool parameters. Per pattern:secret-injection, credentials should use server-side injection via environment variables.
No error handling or recovery guidance. Tools lack descriptions of failure modes, retryability, and what the LLM should do if validation fails or a script cannot be analyzed.
Tool composition unclear. The pipeline (analyze_script → validate_script → generate_comprehensive_report) is not self-evident. No descriptions explain that validate_script requires output from analyze_script, or that generate_comprehensive_report requires validation_result.
Parameter descriptions incomplete or missing. batch_detect has 'script_paths' and 'output_dir' with minimal context. analyze_script parameter 'script_path' lacks format/constraint info. analyze_python_file has 'project_modules' with no type detail (is it a list of strings? list of dicts?).
analyze_python_file appears to accept 'project_modules' as an array but no schema or description specifies what each element contains or represents. LLMs cannot construct valid input.
detect_hallucinations and batch_detect have boolean parameters (save_json, save_markdown, print_summary) with no guidance on what happens if both are false, or what the default behavior should be if omitted.