JWT-based authentication and authorization server for MCP (Model Context Protocol) with role-based access control (RBAC), user management, and permission enforcement. Supports web retrieval via Tavily, vector database integration with Qdrant, caching, rate limiting, and comprehensive logging.
This MCP server exhibits significant definition quality issues across all three tools. While schemas are present and partially documented, descriptions are inadequate (many under 20 characters in Korean, limiting usefulness to English-speaking LLMs), parameter documentation is sparse, and critical security/design concerns are unaddressed. The 'register' tool exposes plaintext password parameters, a serious security anti-pattern. Tool names lack clarity: 'search_web_tool' and 'search_all_tool' violate verb_noun conventions and are difficult to distinguish. No output schemas are documented. Error handling guidance is absent. The server reads as a proof-of-concept rather than production-grade tooling.
새 사용자 계정 등록. 제공된 사용자 정보로 새로운 계정을 생성합니다. 이메일 중복 검사, 비밀번호 해싱, 기본 역할 할당을 수행합니다.
모든 리트리버에서 동시에 검색합니다
웹 검색 도구를 직접 호출합니다
Plaintext password exposed as tool parameter: 'register' tool requires users to pass 'password' directly as input. This violates secret-injection pattern, passwords will be logged in traces, agent histories, and audit trails. Implement server-side password generation or OAuth flow instead.
No output schemas documented for any tool. LLMs cannot reason about downstream tool chaining or extract necessary fields (e.g., what does search_web_tool return? document structure, field names, and types for each result). This violates response-shaper and tool-chain patterns.
Tool naming violates verb_noun convention and lacks clarity. 'search_web_tool' and 'search_all_tool' are redundant suffixes ('_tool') and fail to distinguish intent. Ambiguous names like 'search_all_tool' (search across what? all retrievers? all databases?) force LLMs to guess. Rename to 'search_web' and 'search_retrievers' or similar.
Inferred effective spec: 2026-07-28+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 38 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 37 | - | v1 |
Descriptions are in Korean and many are under 20 characters when translated. English-speaking LLMs cannot effectively parse Korean descriptions. 'search_web_tool: 웹 검색 도구를 직접 호출합니다' (call web search tool directly) is uninformative, it does not explain WHEN to use it, WHAT it returns, prerequisites, or how it differs from 'search_all_tool'. Baselines require 34 - 392 chars with clear context.
Parameter descriptions are missing or minimal. 'include_domains' and 'exclude_domains' lack description text explaining the expected format (CSV list? JSON array?), constraints (max domains? wildcard support?), and use cases. LLMs cannot infer parameter semantics from names alone.
No error handling or recovery guidance. If 'register' fails due to duplicate email, does the tool return an error message? Can the LLM retry? Should it suggest calling search_users first? No documentation. If search_all_tool times out, should the agent treat it as retryable or fatal? Unclear.
No permission/scope declarations. Which tools require authentication? Are 'search_web' and 'search_all' public, or restricted? Does 'register' require admin role? No clear scope model or permission checks visible in tool definitions.
Parameter type definitions incomplete for 'register'. 'password' is a string, but no regex pattern, length constraint, or complexity requirement is documented. Schema shows only type: 'string', no minLength, pattern, or description of '(最小 8字, 複雑度要件)' from the Korean text. LLMs cannot enforce password policy.
No idempotency contract. Is calling 'register' twice with the same email safe? Does it return an error, or create a duplicate? Can the LLM safely retry on network failure? No documentation.
Missing pagination support. If 'search_web_tool' returns hundreds of results, how does the LLM access page 2? No 'page', 'offset', 'limit', or 'next_cursor' parameter visible. Large uncontrolled result sets blow context windows.