MCP server for Tenzir that provides tools for data pipeline operations, OCSF mapping, documentation search, and code generation
The server has 4 tools with mixed quality. Naming is acceptable (verb-noun pattern mostly followed), but parameter schemas are minimally visible in the provided source. Descriptions exist but are moderately detailed. Critical issue: only 1 input parameter visible per tool (all 'sample' string), and the source code is truncated, preventing full schema assessment. Tool annotations are declared (readOnlyHint, idempotentHint, openWorldHint present in make_ocsf_mapping), which is good. However, parameter descriptions are minimal (one-liners), and output schemas are not documented in the visible code. Error handling and recovery guidance are not visible. Overall, this is a borderline poor-to-fair MCP server, it has the structure but lacks depth in parameter documentation and output schema clarity.
Read documentation content from the embedded Tenzir documentation. Use this tool to: - Read operator documentation BEFORE using any TQL operator - Read function documentation BEFORE using any TQL function - Study tutorials and guides for learning workflows
Add OCSF mapping to a TQL parsing pipeline. Use this tool when: - You need to map security logs to the OCSF standard - You're normalizing data from multiple sources into a common schema - You want to make your data compatible with OCSF-aware tools - You need guidance on OCSF class selection and field mapping Follow the workflow instructions provided in the response.
Generate a TQL parser for the given log format. Use this tool when: - You have sample log events and need to parse them into structured data - You're starting a new parser for JSON, CSV, syslog, or key-value logs - You want guidance on format detection and TQL operator selection - You need to infer types and create proper schema transformations This tool provides a complete workflow with step-by-step instructions for: 1. Analyzing log format and structure 2. Selecting appropriate TQL operators 3. Generating parsing code with type conversions 4. Creating a package with the parser 5. Testing the parser with sample data Follow the workflow instructions provided in the response.
docs_search tool has NO visible description or schema in provided source code. Cannot assess completeness.
All tools have minimal parameter descriptions (single short sentence). Descriptions lack context about expected format, range, examples, or when to use each parameter.
Output schemas are not documented anywhere in visible source. Tools return ToolResult but the structure and fields are not declared. LLMs cannot plan downstream tool chains without knowing what fields to extract.
Error handling and recovery guidance are not visible in provided code. No evidence of actionable error messages that tell the LLM what to do next.
Inferred effective spec: 2025-06-18+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2025-06-18+ | v2 |
| 2026-03-09 | F | 41 | - | v1 |
Tool names are generic and do not clearly convey action scope. 'make_parser' and 'make_ocsf_mapping' could be clearer: 'generate_tql_parser' and 'generate_ocsf_mapping' would better signal code generation intent.
Source file for make_ocsf_mapping is truncated mid-code. Cannot verify full implementation, parameter validation, or error handling.