FastAPI-based MCP server for Docker filesystem operations and Manim animation rendering
The Manim MCP server has only 2 tools with partial schema visibility and significant documentation gaps. Both tools have descriptions and parameter schemas visible in the code, but descriptions are minimal/generic, and several critical parameter constraints are missing or underdocumented. The write_file tool has a concerning nested object structure ('file_data' containing 'content') that complicates the schema. Error handling exists but lacks recovery guidance. Security measures are present (path traversal checks, allowed base directories) but not systematized. No tool annotations (readOnlyHint, destructiveHint, idempotentHint) are used. The average per-tool score is 42, placing this in the 'Poor' (50-59) range, trending slightly lower due to schema complexity and missing parameter documentation.
List files and directories in the Docker container filesystem. Security restrictions: Only allowed base directories can be accessed, Path traversal attempts are blocked, Certain system directories are inaccessible
Write content to a file in the Docker container filesystem. Security restrictions: Only allowed base directories can be written to, Path traversal attempts are blocked, Existing files are not overwritten unless explicitly specified
Missing tool annotations (readOnlyHint, destructiveHint, idempotentHint). write_file is destructive but not marked as such; list_files is read-only but not annotated.
write_file lacks destructive operation safeguards. No mention of dry-run, confirmation, or undo capability. Agents may accidentally overwrite critical files without warning.
Parameter 'file_data' is nested object structure (object with 'content' subfield). This is awkward, should flatten to a single 'content' string parameter for clarity and ease of LLM reasoning.
Missing parameter constraints: 'max_depth' has no documented min/max; 'pattern' does not specify glob syntax details; 'content' (in file_data) has no size limit or encoding specification.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 55 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 25 | - | v1 |
Error handling returns HTTPException with basic messages but lacks recovery guidance. E.g., 'Access is only allowed to these base directories...' does not suggest WHAT directory to use next.
Output schemas for both tools are not formally documented in descriptions. list_files returns 'results' array with objects like 'name', 'path', 'size', but field types and detailed schema are not visible.
Idempotency not addressed. write_file with overwrite=true may produce different behavior on retry if file has been deleted or modified in between. No explicit statement of idempotent behavior.