This server exhibits significant quality gaps across naming, descriptions, parameters, schemas, and error handling. While tool names follow the verb_noun pattern correctly (get_packages, execute_adb_shell_command, etc.), the implementations lack rigor in critical areas. Most tools have minimal descriptions (50-80 chars, well below the 194-char baseline for production tools). Parameter schemas are present but descriptions within schemas are sparse or missing. No output schemas are documented. Error handling is entirely absent, tool implementations do not validate inputs, provide recovery guidance, or categorize errors. The server exposes a high-risk tool (execute_adb_shell_command) that accepts arbitrary shell commands with no input sanitization or permission gating, violating pattern:secret-injection and pattern:tool-gateway. No support for modern MCP patterns: no tool annotations (readOnlyHint, destructiveHint, idempotentHint), no Multi-Round-Trip Requests, no per-request _meta or logLevel. Transport is STDIO only, which hard-caps protocol readiness at 50.
Executes an ADB command and returns the output or an error. Args: command (str): The ADB shell command to execute Returns: str: The output of the ADB command
Get all non-data actions from Activity Resolver Table for a package Args: package_name (str): The name of the package to get actions for Returns: list[str]: A list of all non-data actions from the Activity Resolver Table for the package
Get all installed packages on the device Returns: str: A list of all installed packages on the device as a string
Takes a screenshot of the device and returns it. Returns: Image: the screenshot
Retrieves information about clickable elements in the current UI. Returns a formatted string containing details about each clickable element, including its text, content description, bounds, and center coordinates. Returns: str: A formatted list of clickable elements with their properties
execute_adb_shell_command accepts arbitrary shell commands with no input validation, sanitization, or permission gating. This violates pattern:secret-injection (no secrets exposed) but critically violates pattern:tool-gateway (command injection attack surface). An agent could execute 'rm -rf /', leak credentials, or execute malicious payloads. The tool must implement allowlist validation and document which commands are permitted.
No tool descriptions exceed 80 characters; baseline for production tools is 194 chars. Descriptions like 'Takes a screenshot of the device and returns it.' (55 chars) lack context for when to use the tool vs alternatives, expected format of return values, or prerequisites.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 36 | - | v1 |
No output schemas documented. Tools return str, list[str], and Image, but LLMs do not know what fields to expect in structured responses. get_screenshot returns Image(path='...'), but no schema explains the Image type, format, encoding, or dimensions. Per pattern:tool, LLMs need documented schemas to plan chaining calls and extract correct data.
Zero error handling. No validation of input parameters (e.g., execute_adb_shell_command does not check command for illegal characters or size limits). No error recovery guidance in implementations. When deviceManager.get_packages() fails (e.g., device disconnected), the server returns a Python exception/stack trace, not actionable guidance. Per pattern:recovery-guide, errors must tell the LLM what to do next.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint). While get_packages and get_screenshot are read-only, execute_adb_shell_command is marked WRITE in risk but has no destructiveHint annotation to signal to the agent it may modify state. Per current MCP spec (2026-07-28), tool annotations guide agent reasoning and plan generation.
Parameter schemas present but descriptions within schemas are minimal or missing context. For example, execute_adb_shell_command's 'command' param has description 'The ADB shell command to execute' (41 chars), but does not specify format, length limits, allowed/forbidden commands, or examples of valid invocations.
No pagination support for tools that return large lists. get_packages returns all packages as a newline-delimited string without limit, offset, or pagination markers. A device with 300+ packages will produce a response that bloats context window. Per pattern:paginated-result, tools returning lists must accept limit/offset and include a total count.
No permission gating or audit logging. The server does not verify the calling agent has authority to execute arbitrary ADB commands. No logs record which agent called which tool with which parameters. Per pattern:permission-gate and pattern:audit-trail, destructive or sensitive tools must be gated and all calls traced for compliance.