A Model Context Protocol daemon server that manages and exposes MCP servers, tools, prompts, and resources through an HTTP API
mcpd is a meta-MCP server (a proxy/gateway for discovering and calling other MCP servers). It has 3 tools with moderate-to-good naming and descriptions, but lacks critical schema documentation and parameter descriptions. Tools are visible in internal/api/tools.go and internal/api/servers.go. All tools have basic descriptions (68 - 106 chars), meeting the 10 - 1024 char range, but parameter details are sparse. The 'callTool' tool accepts an open-ended 'body' object with no schema constraints, which is a high-risk pattern for composition. Output schemas are not documented anywhere in the provided source. Tool names follow verb_noun convention (listTools, callTool, listServers), which is good. However, parameter descriptions are either missing or minimal, violating the pattern:tool-description requirement. This server would benefit from explicit JSON Schema definitions for all parameters and documented output schemas.
Call a tool on a specified server
List all configured MCP servers
List server tools with configurable detail level via ?detail= query parameter (minimal, summary, full)
callTool accepts 'body' parameter as open-ended object with no schema constraints. LLMs cannot determine what fields are valid without explicit schema documentation. This violates pattern:constrained-input and invites hallucinated payloads.
Output schemas are not documented for any tool. LLMs cannot plan downstream tool calls or extract needed fields without knowing what each tool returns. Violates pattern:tool.
Parameter descriptions are missing or minimal. 'detail' parameter in listTools has a description, but 'server' and 'tool' parameters in callTool lack descriptions explaining what 'server' refers to (is it a name, ID, URL?). Violates pattern:tool-description.
No error handling guidance documented. If callTool fails (network error, invalid tool, permission denied), there is no indication of what the LLM should do next. Violates pattern:recovery-guide.
Inferred effective spec: 2025-06-18+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 69 | 2025-06-18+ | v2 |
| 2026-03-09 | D | 51 | - | v1 |
callTool is a high-risk tool that executes arbitrary code on remote MCP servers. No mention of permission checks, rate limits, or audit logging. Violates pattern:permission-gate and pattern:audit-trail.