A C# .NET-based Model Context Protocol server providing Docker development container management, Git operations, and file system integration for AI agents.
This MCP server exposes 7 tools for Docker dev container and Git operations. While the tools are registered with the [McpServerTool] attribute and have descriptions, there are critical structural and documentation gaps that prevent reliable LLM integration. Transport is unknown (likely STDIO based on the C# custom framework and lack of HTTP evidence), which is a hard blocker. Tool schemas are inferred from method signatures rather than explicit JSON Schema definitions, the parameter types exist in C# but are not exposed as machine-readable schemas in the MCP protocol. Descriptions are shared across multiple tools (the DevContainerTool.cs class uses identical descriptions for all three methods), violating the single-responsibility principle and confusing LLM tool selection. Parameter descriptions are minimal or absent. No input validation examples, error handling patterns, or recovery guidance are visible. The tools expose dangerous operations (container deletion, arbitrary command execution, Git push) without documented permission gates, confirmation mechanisms, or audit patterns. CancellationToken parameters should never be exposed to agents.
Provides tools to execute common Git commands inside Docker development containers. Enables agents and tools to perform repository operations such as clone, checkout, commit, and push within a specified dev container.
Provides operations to create and remove Docker development containers for agents and tools.
Provides tools to execute common Git commands inside Docker development containers. Enables agents and tools to perform repository operations such as clone, checkout, commit, and push within a specified dev container.
Provides tools to execute common Git commands inside Docker development containers. Enables agents and tools to perform repository operations such as clone, checkout, commit, and push within a specified dev container.
Provides operations to create and remove Docker development containers for agents and tools.
Provides tools to execute common Git commands inside Docker development containers. Enables agents and tools to perform repository operations such as clone, checkout, commit, and push within a specified dev container.
Identical descriptions across multiple tools violate single-responsibility principle. DevContainerTool, CleanupDevContainerAsync, and RunCommandInDevContainerAsync all share the same description ('Provides operations to create and remove Docker development containers...'), making it impossible for LLMs to distinguish when to call each tool.
No explicit JSON Schema definitions visible. Parameters exist in C# method signatures but are not registered as structured JSON Schema in the MCP protocol. The schema type 'CancellationToken' is exposed as a parameter, which should never be exposed to agents, this is a framework implementation detail.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 28 | 2025-06-18+ | v2 |
| 2026-03-09 | F | 28 | - | v1 |
Provides operations to create and remove Docker development containers for agents and tools.
Dangerous operations (delete containers, arbitrary command execution, Git push) lack confirmation mechanisms, permission checks, or audit logging. CleanupDevContainerAsync is marked Destructive=true but has no documented recovery path or user confirmation step.
Parameter descriptions are missing or empty. 'containerName' in CleanupDevContainerAsync has an empty description. 'command' parameter in RunCommandInDevContainerAsync has no explanation of format, escaping, or safety constraints.
No error handling or recovery guidance visible. Tools return Task<string> but no documentation explains what success/failure looks like, when to retry, or what the LLM should do on error.
Tool names do not follow verb_noun convention. 'CreateDevContainerAsync' should be 'create_dev_container'. 'CleanupDevContainerAsync' is vague, is it 'delete', 'stop', or 'clean'? Multi-word method names without clear verb-object structure confuse LLM tool selection.
Output schemas are not documented. All tools return Task<string>, but there is no specification of what the string contains (JSON, plain text, error code?). Without documented output schemas, LLMs cannot plan downstream operations or extract structured data.