This server exposes 12 tools for Weik.io CLI integration and Apache Camel metadata. All tools are explicitly registered in src/index.ts with names, descriptions, and input schemas. However, significant gaps in schema completeness, parameter descriptions, and output documentation drag the overall score down. Most tools lack detailed parameter constraints and none document return types. Descriptions are present but often generic (averaging ~80 chars). Parameter descriptions are sparse or missing entirely, critically, parameters like 'filepath', 'query', and 'name' lack format constraints, validation rules, or usage examples. No tool documents what it returns or its data structure. Error handling is minimal (generic McpError wrapping). The server follows a STDIO transport pattern, which hard-caps Protocol Readiness at 50 and makes it unsuitable for hosted MCP clients.
Parameter descriptions are missing or severely undescribed. 'query' parameter (search_components, search_kamelets) lacks any guidance on syntax, scope (name vs description vs label), or example values. 'filepath' in apply_config lacks format requirements (absolute vs relative, extension validation, existence check). 'name' in add_profile, initialize_integration, push_integration lacks validation rules or constraints. LLMs cannot infer what to pass without explicit descriptions.
No tool documents its output schema or return type. LLMs need to know what fields to expect from list_agents, get_component_details, get_kamelet_details, etc. Without documented return types, agents cannot plan downstream calls or extract necessary fields. This violates DIMENSION 1.D (Schemas & Output).
Add detailed parameter descriptions for every input. For 'query' parameters, specify: 'Search term matched against component name, description, and labels. Use wildcards (*) for partial matches. E.g., 'http*' matches http, https, httpcomponent.' For 'filepath', specify: 'Absolute or relative path to YAML config file (must end in .yaml or .yml; file must exist; must be readable).' For 'name', specify: 'Integration name (lowercase, 2-50 chars, alphanumeric + hyphens only; must be unique within the target directory).'
Document the output schema for every tool. For list_agents, return something like: '{"agents": [{"name": "string", "id": "string", "status": "active|inactive", "createdAt": "ISO 8601 date"}], "total": "integer"}'. For search_components, return: '{"components": [{"name": "string", "description": "string", "labels": ["string"]}], "count": "integer"}'.
Move the 'apiKey' parameter in add_profile to server-side secret injection. Modify the input schema to remove 'apiKey' and document in the tool description: 'Note: Credentials are configured via environment variable WEIKIO_API_KEY or vault. This tool uses the pre-configured API key.' Store credentials in the server environment, not the tool parameter.
Add enums and constraints to parameters. For search results, add optional 'limit' (default 20, min 1, max 100) and 'offset' (default 0, min 0) parameters with descriptions: 'Maximum number of results to return (default 20). Results are paginated to avoid context overflow.' For name fields, use a regex pattern in the schema: '"pattern": "^[a-z0-9-]{2,50}$"' and describe in the parameter: 'Must be 2-50 chars, lowercase alphanumeric and hyphens only.'
Score history
Overall score trend
↑ 44 points across a rubric change (v1 → v2)
44/100
Scored
Grade
Overall
Spec posture
Rubric
2026-09-22
F
44
2026-07-28+
v2
2026-03-09
F
0
-
v1
list_agentsread onlyauthsource verified57/100
List all Weik.io agents
list_profilesread onlyauthsource verified57/100
List all Weik.io profiles
push_integrationwriteauthsource verified50/100
Push an integration to a Weik.io instance
search_componentsread onlysource verified48/100
Search for Apache Camel components by name, description, or label
search_kameletsread onlysource verified48/100
Search for Apache Camel Kamelets by name, title, or description
Parameter 'apiKey' in add_profile is exposed as a tool parameter. Credentials must never appear as tool parameters, they should be injected server-side via environment variables or vault. Agent traces log every parameter, risking credential leaks.
No input validation or constraint documentation. Parameters like 'name' (initialize_integration) claim to be 'lowercase, can include hyphens' but this is buried in the description and not enforced as a regex pattern or constraint. 'page_size', 'limit' style bounds are absent from all tools. No enums for constrained values.
Error handling is minimal and unhelpful. The executeWeikioCommand function wraps all errors in a generic McpError(ErrorCode.InternalError, ...). There is no guidance on recovery, no distinction between retryable vs user-fixable errors, no actionable error messages. An LLM receiving 'Weik.io CLI error: command not found' cannot self-correct.
Destructive tools (apply_config, push_integration, add_profile, initialize_integration) lack confirmation or dry-run support. Agents can accidentally apply configs, push untested integrations, or overwrite profiles without explicit user approval. No idempotency guarantees documented.
Tool descriptions are generic and lack WHEN-to-use guidance. 'List all Weik.io agents' does not explain when an agent should call this vs a discovery tool. 'Get detailed information about a specific Apache Camel component' does not explain the relationship to search_components or what 'detailed' means. LLMs need explicit disambiguation.
No pagination support documented. Tools like list_agents and list_profiles return unbounded results. If there are hundreds of agents or profiles, the LLM will receive all of them, exhausting context. No 'limit', 'offset', 'page', or 'cursor' parameters are present.
Implement proper error handling with actionable recovery guidance. Replace generic InternalError wraps with specific errors: if 'command not found', return 'Weik.io CLI not installed. Install with: npm install -g weikio-cli or run this server in the provided Docker container.' If 'file not found', return 'Config file not found at {filepath}. Provide an absolute path or relative path from the current working directory.' Use ErrorCode.InvalidRequest for bad inputs (validation failures), ErrorCode.InternalError for service unavailability.
Add optional dry-run or confirmation for destructive tools. Modify apply_config to accept an optional 'dry_run' boolean parameter (default false) with description: 'If true, validate the config without applying it. Use this to check for errors before committing changes.' Modify push_integration to return a confirmation step: if the user hasn't explicitly set 'confirm=true', return a structured error asking for confirmation: '{"type": "confirmation_required", "message": "Push integration \"my-integration\" to {url}? This cannot be undone.", "requiresConfirmation": true}'.
Improve tool descriptions to include WHEN-to-use and prerequisites. For list_agents, change to: 'List all Weik.io agents configured in the current profile. Call this first to discover available agents before calling apply_config or push_integration. Requires an active Weik.io profile (use list_profiles to check).' For search_components, change to: 'Search for Apache Camel components by name, description, or label. Use this to discover available connectors before designing an integration. Returns up to 20 results; use offset and limit for pagination.'
Add result limits and pagination guidance. All list_* and search_* tools should document: 'Returns up to 20 results by default. Use the offset and limit parameters to fetch additional pages. For example, to get results 20-40, pass offset=20&limit=20. A total count is returned so you can determine if more results exist.'
Document idempotency and side effects. For initialize_integration, specify: 'Creates a new integration directory structure. Idempotent: calling with the same name and directory will fail if the directory already exists (to prevent overwrites). For push_integration, specify: 'Uploads the integration to the configured Weik.io instance. NOT idempotent: calling twice will create two separate integration versions. Use dry_run=true first to validate before pushing.'
Add tool annotations for read-only vs destructive. Use tool metadata (when available in MCP SDK) to mark: list_agents, search_components, get_component_details, search_kamelets, get_kamelet_details, get_docker_compose, list_profiles as read-only. Mark apply_config, add_profile, initialize_integration, push_integration as destructive. This helps agents reason about side effects and retry safety.