MCP agent providing cost-aware guardrails for IaC in CI/CD
FinOpsGuard defines 12 tools with reasonable naming conventions and domain-specific descriptions, but suffers from incomplete schemas, missing parameter descriptions, and insufficient error handling guidance. Tool names follow verb_noun patterns (checkCostImpact, suggestOptimizations, etc.), which is good. However, input schemas are inferred from the request classes rather than explicitly visible in tool registration. The source code shows incomplete parameter documentation, many parameters lack detailed descriptions explaining format, constraints, or valid ranges. Output schemas are not documented anywhere in the visible code. Error handling is minimal; there's one HTTPException pattern visible but no recovery guidance. The server uses FastAPI's implicit schema generation from Pydantic models, which is better than nothing, but actual parameter constraints (min/max, enums, patterns) are not visible in the provided code. Risk annotations are present (READ_ONLY, WRITE, DESTRUCTIVE) but not formally integrated into schema definitions.
Get cache statistics and information
Check cost impact of IaC changes
Create a new policy
Delete a policy by ID
Evaluate policy against IaC
Flush all cached data (admin operation)
Prometheus metrics endpoint
Get a specific policy by ID
Get price catalog for cloud resources
Output schemas not documented. No visible return type documentation for any tool. LLMs cannot infer what fields to expect, breaking downstream tool chaining and forcing unnecessary discovery calls.
Parameter descriptions incomplete or missing constraint information. Parameters like 'limit', 'offset', 'budget', 'cloud_provider' lack explicit ranges, enums, or format specifications. E.g., 'limit' should state 'integer, 1-100' but only says 'Maximum number of analyses to return'.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 13 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 37 | - | v1 |
Health check endpoint
List all policies
List recent cost analyses
MCP Protocol Information - Returns information about available MCP endpoints and the protocol version
Suggest cost optimizations
Update an existing policy
Error handling lacks recovery guidance. HTTPException with generic 'internal_error' in checkCostImpact tells LLM nothing actionable. No pattern for retryable vs fatal errors, no suggestions for alternatives.
flushCache tool description is vague ('Flush all cached data') and name lacks clarity ('flush' is ambiguous). What actually happens? Is this idempotent? What are the consequences? No LLM can use this safely.
No documented pagination strategy visible. listRecentAnalyses accepts limit/offset but no documented max page size, total count, or next_cursor patterns. Large result sets risk context window overflow.
deletePolicy offers no confirmation or dry-run pattern. Destructive operations should support a safety mechanism to prevent accidental deletion by agents.
Tool annotations present in metadata (READ_ONLY, WRITE, DESTRUCTIVE) but not formally declared in schema. Modern MCP clients expect readOnlyHint, destructiveHint annotations in tool definitions, not external metadata.
Input schema clarity issue: 'on_violation' parameter in createPolicy describes as 'blocking or advisory' but no enum constraint visible. LLM may hallucinate other values (e.g., 'warn', 'notify').