Official MCP server for CyberEdu CTF platform. Automatically discovers and exposes all CyberEduClient methods as MCP tools, including session management, challenge browsing, file downloads, flag submission, contest participation, and service management.
CyberEdu MCP provides 20 tools with generally complete schemas and descriptions. Tool naming follows verb_noun conventions consistently (cyberedu_set_session_cookie, cyberedu_list_challenges, cyberedu_get_challenge, etc.). All tools have non-empty descriptions (baseline: 100% have descriptions). Input schemas are properly structured with type definitions and required field declarations. However, several gaps reduce quality: (1) descriptions vary in LLM-optimization, some are verbose while others lack context about when/why to call the tool; (2) parameter descriptions are present but some lack detail about constraints, ranges, or format; (3) output schemas are not documented, LLMs cannot know what fields will be returned; (4) error handling guidance is absent, tools do not indicate what to do on failure or how errors are classified; (5) no tool annotations (readOnlyHint, destructiveHint, idempotentHint) despite clear WRITE vs READ_ONLY risk levels in metadata. Per-tool analysis: naming is consistently strong (100% verb_noun), descriptions average ~180 chars (within baseline 194), schemas are well-formed with types, but descriptions lack LLM-optimization hints for multi-tool scenarios (e.g., 'Call cyberedu_list_tenants first to see available options' is missing from cyberedu_switch_tenant).
Clear stored session credentials from disk. This removes the persisted session cookie and tenant from disk. The current in-memory session remains active until the MCP server restarts. Use this when you want to remove stored credentials for security.
Download a file associated with a challenge. Files are referenced by their UUID identifiers from the challenge details. Can optionally save directly to disk by providing a save_path parameter.
Extend the running time of a challenge service before it expires. Useful when you need more time to solve a challenge.
Get detailed information about a specific challenge in the educational archive. Returns description, categories, difficulty, files available for download, flag submission status, and any hint information.
Get detailed information about a specific contest. Returns contest details, challenge list, standings, and participation status.
Get detailed information about a specific challenge within a contest. Similar to get_challenge but includes contest-specific metadata.
Output schemas not documented. Tools do not declare what fields they return, preventing LLMs from planning downstream calls and extracting relevant data. Per pattern:tool-chain, broken response chains force discovery detours.
Tool annotations missing. Tools are marked READ_ONLY or WRITE in metadata but lack MCP tool annotations (readOnlyHint, destructiveHint, idempotentHint). Agents cannot determine from schema alone which tools mutate state.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 48 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 33 | - | v1 |
Get the contest leaderboard/standings. View rankings and scores of all participants in a contest.
Check the status of a running challenge service within a contest.
Check the status of a running challenge service. Returns information about whether the service is running, when it expires, and how to connect to it.
Get current session status. Shows whether you're authenticated, which tenant is selected, and whether credentials are persisted to disk.
Browse all available challenges in the educational archive. Retrieve a paginated list of challenges with filtering by category, difficulty, and search. Use this to discover available CTF challenges.
List all available contests/events. See what CTF competitions are available to participate in.
List all available tenants/organizations. Shows what tenants you have access to for switching.
Restart a running challenge service. Use this if the service becomes unresponsive or you need to reset it.
Set the session cookie for authentication. This allows you to authenticate without restarting the MCP server. The cookie is persisted to disk (~/.cyberedu-mcp/session.json) and will be automatically loaded in future sessions. Get your session cookie from browser developer tools after logging in to https://app.cyber-edu.co (look for the 'cyberedu_session' cookie).
Start a challenge instance service within a contest. Similar to start_service but for contest challenges.
Start a challenge instance service. Many challenges require running a service to interact with. Services have a time limit and will automatically expire.
Submit a flag for a challenge in a contest. Check contest challenge details for the expected flag format.
Submit a flag for a challenge in the educational archive. Check challenge details to understand the expected flag format (typically CTF{...}).
Switch to a different tenant. Use this to change which tenant/organization you're working with. The tenant selection is persisted to disk for future sessions. You can list available tenants using 'cyberedu_list_tenants'.
Error handling guidance absent. No tool description explains what happens on failure, how to classify errors (retryable vs user-fixable vs fatal), or what to do next. Per pattern:recovery-guide, error responses must guide the agent's next step.
Parameter descriptions lack LLM-optimization context. Many parameters lack detail about valid ranges, formats, constraints, or dependencies. E.g., 'skip' and 'limit' parameters in list_challenges do not specify min/max bounds; 'difficulty' filter does not enumerate valid difficulty levels.
Descriptions lack dependency hints. E.g., cyberedu_switch_tenant does not mention 'Call cyberedu_list_tenants() first to see available options.' Per pattern:tool-description, discovery hints prevent wasted calls and guide multi-step planning.
Pagination details incomplete. List tools (cyberedu_list_challenges, cyberedu_list_contests, cyberedu_list_tenants) accept skip/limit but descriptions do not state: (1) what total count is returned, (2) whether a next_cursor is available, (3) result count caps. Per pattern:paginated-result, agents need to know when they've received the last page.
No confirmation step for destructive operations. Tools like cyberedu_clear_session, cyberedu_restart_service, and cyberedu_submit_flag (irreversible contest submission) lack a dry-run or confirmation mechanism. Per pattern:confirmation-request, agents make mistakes, provide a safety net.
Parameter naming consistency issue in contest tools. Tools use both 'contest_slug' and 'challenge_id' naming, which is correct, but some descriptions do not clarify that contest_slug must be obtained from cyberedu_list_contests first. This creates implicit dependencies.