The server defines 5 tools with clear verb-based names (list_, describe_, execute_, get_) and descriptions present for all tools and most parameters. However, significant gaps exist: output schemas are not documented anywhere (tools return JSON strings, not structured CallToolResult objects with defined fields), parameter descriptions lack format/constraint details, and error handling provides minimal recovery guidance. The tools are well-intentioned database explorers but fall short of production-grade specification rigor. No tool annotations (readOnlyHint/destructiveHint) are present despite clear READ_ONLY risk profiles.
Get the structure of a specific table
Execute a read-only SQL query (SELECT, SHOW, DESCRIBE, EXPLAIN, USE)
Get the total row count of a table
Get sample rows from a table
List all tables in the database
Output schemas completely undocumented. No tools declare what fields they return. LLMs cannot plan downstream operations or extract required data without seeing CallToolResult structure.
No tool annotations present (readOnlyHint, destructiveHint, idempotentHint). All 5 tools are READ_ONLY but this is not formally declared in the MCP schema. Agents cannot distinguish read vs. write tools without annotations.
Parameter descriptions lack format/constraint details. 'limit' (get_table_sample) has no range, default behavior is only mentioned in description text (default: 100), not enforced. 'table_name' and 'query' have minimal guidance on format/character limits.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 53 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 49 | - | v1 |
Error responses are generic ('Failed to list tables: %v', 'Query failed: %v'). Errors do not guide recovery. If a table is not found or query is invalid, LLM receives no actionable next step.
execute_query accepts ANY SQL query but description says 'read-only' and lists allowed statement types. No input validation enforces these constraints. LLM could be tricked into running INSERT/UPDATE/DELETE despite policy.
Tool descriptions are functional but brief (30-60 chars). Lack context on WHEN to use each tool vs. alternatives. E.g., when should agent use execute_query vs. get_table_sample vs. get_table_count? Descriptions do not disambiguate.