A Python-based MCP server providing code analysis, URL routing lookup, file operations, web automation, and database access tools for development workflows
This server exhibits significant structural deficiencies across definition quality dimensions. Of 23 tools, schemas are largely absent or minimal (only basic parameter types visible, no output schemas documented), descriptions range from adequate to vague, and critical patterns are missing. The codebase shows heavy reliance on Google ADK framework (google.adk.tools) but tool registration mechanics are not clearly visible in provided source. Most tools lack the LLM-optimized descriptions required for reliable agent selection. Error handling guidance is absent. No tool annotations (readOnlyHint/destructiveHint) despite mixing read/write/destructive operations. Several tools conflate multiple responsibilities (e.g., analyze_webpage_and_determine_action both analyzes AND suggests actions).
Analyze video content including transcript and visuals from MP4 files or YouTube URLs using Google Vertex AI and Gemini.
Extract and analyze only the transcript from a video with timestamps and speaker identification.
Analyze only the visual content of a video (no audio/transcript).
Analyzes the webpage and determines the next action (scroll, click, enter text, etc.) to achieve a user task.
Clicks at the specified coordinates on the screen and scrolls to that position.
Clicks on an element on the page with the given text.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint) despite mixing read/write/destructive operations. Critical for agent safety, LLM cannot distinguish safe tools from destructive ones without explicit hints.
Output schemas absent or undocumented for all 23 tools. LLMs cannot plan downstream tool chains without knowing what fields to expect. Breaks pattern:tool-chain composability.
Raw SQL string parameters (db_read_tool, db_write_tool) with no validation, SQL injection risk. Violates pattern:tool-gateway (sanitization of untrusted input).
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 45 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 34 | - | v1 |
Provides read-only access to the database to validate data, verify states, compare expected vs actual values, and identify missing or malformed entries.
Provides admin-level write access to the database to fix incorrect values, update states, and repair inconsistent records. Requires admin approval.
Delete a file from the repository.
Enters text into an element with the given ID.
Extract a function or method source code by name. Returns source code, line numbers, and optionally helper functions discovered from calls inside the target.
Given a file path and function name, returns the full source code of the function, helper functions called inside it, and its docstrings and module context.
Finds an element on the page with the given text using XPath.
Get the lookup URL from a Full URL. Returns matched route and extracted parameters from Django URL routing.
Returns the current page source (HTML) from the browser.
Navigates the browser to the given URL using Selenium WebDriver.
List contents of a directory in the repository. Supports recursive listing and filtering of hidden files.
Performs a long-running code scan or analysis operation involving static analysis and dependency graph generation.
Read the contents of a file in the repository. Returns file contents, encoding info, and status.
Scrolls down the screen by a moderate amount (500 pixels).
Uses Selenium to reproduce UI flows, test button clicks & form submissions, inspect CSS/JS behavior, capture screenshots, and extract HTML snippets.
Takes a screenshot and saves it as a PNG artifact. Uses Selenium WebDriver.
Write content to a file in the repository. Creates parent directories if they don't exist.
Destructive operations (delete_file, db_write_tool) lack confirmation/dry-run support. No recovery guidance or per-item success/failure reporting. Violates pattern:confirmation-request.
Generic tool names violate verb_noun convention: 'db_read_tool', 'db_write_tool', 'selenium_scraper_tool'. Should be 'query_database', 'write_database', 'scrape_page_with_selenium'. LLM cannot infer action from generic names.
Compound tool responsibility: analyze_webpage_and_determine_action combines analysis AND action suggestion. Should split into analyze_webpage + suggest_next_action. Violates single-responsibility principle (pattern:tool).
Duplicate/near-duplicate tools: extract_function_source_ast (#2) and extract_function_source_tool (#23) appear nearly identical. LLM will waste reasoning cycles choosing between them. Requires consolidation and clear differentiation.
Descriptions are generic and lack LLM-optimized context. Average ~55 chars (rubric baseline 194 chars, p10=34, p90=392). Missing WHEN to use, prerequisites, and downstream expectations. Examples: 'Delete a file', 'Navigates browser to URL', 'Read the contents of a file'.
Parameters lack validation constraints and ranges. Examples: click_at_coordinates (x, y), no bounds documented; scroll_down_screen, hardcoded 500px, no flexibility; text_to_enter, no length or encoding constraints. LLM will pass invalid values.
No error handling guidance or recovery patterns documented. Silent failures, unrecoverable errors, or retry guidance missing. Violates pattern:recovery-guide. Examples: find_element_with_text (what if not found?), db_read_tool (what if query fails?).
Tools requiring external services (Selenium, Google Vertex AI, Gemini) lack clear dependency documentation or initialization prerequisites. No timeout or availability checks documented.