FastAPI backend for testing MCP servers with multiple LLM providers (Groq, OpenAI, Anthropic). Discovers MCP tools and bridges them to LangChain for agent-based execution.
MCP Lab exposes only 2 tools with extremely limited definition quality. The 'discover_tools' tool lacks parameter description, and 'call_tool' has only basic parameter descriptions. Neither tool has documented output schemas. The code shows incomplete tool registration (mcp_tools_bridge.py has truncated function definition) and no structured error handling or recovery guidance. Tool naming follows verb_noun convention but descriptions are minimal. No security considerations are evident for a tool that executes arbitrary MCP server operations. The server appears to be a bridge that dynamically wraps external MCP tools but fails to apply proper definition quality standards to its own exposed interface.
Execute a tool from an MCP server with given arguments
Discover and create LangChain tools from all MCP servers
Neither tool documents output schema. LLMs cannot plan downstream calls or extract needed fields without knowing response structure.
discover_tools description is only 57 chars: 'Discover and create LangChain tools from all MCP servers'. This is below the 10-1024 guideline lower bound and provides minimal context for when/why an LLM should call it.
call_tool description (96 chars) lacks critical detail: no mention of side effects (WRITE risk), prerequisites (must call discover_tools first?), or error handling guidance. Agents need to know this tool modifies state.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 40 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 25 | - | v1 |
call_tool input schema partially visible: 'server' and 'tool_name' lack descriptions; 'kwargs' is described as 'Tool arguments' but no type/structure is defined (is it a dict? object schema?). Parameter descriptions must be provided for all params.
call_tool accepts arbitrary 'kwargs' without input validation, sanitization, or injection protection. LLMs can be tricked into passing malicious payloads; tool should validate against discovered schema from discover_tools.
No error handling or recovery guidance in tool descriptions. If call_tool fails (unknown server, invalid tool, execution error), the description does not tell LLM what to do next or how to retry.
Tool composition risk: discover_tools and call_tool are tightly coupled but this dependency is not documented. An LLM must call discover_tools first to learn valid server/tool_name combinations, but neither tool description states this prerequisite.
Security: No mention of permission gates, scope declarations, or audit trails. A tool that executes arbitrary operations from external MCP servers should declare required permissions (read/write/execute) and log who called what.
Source code truncation in mcp_tools_bridge.py at the coroutine definition suggests incomplete implementation visible. Cannot verify full tool registration or async execution model.