AI-powered CLI coding assistant with MCP tool system for code analysis, generation, and various programming tasks
Codexa exhibits severe definition quality gaps across all four tools. While tool names follow verb_noun convention (ai_code_generation, ai_text_generation, bash), the actual implementation reveals critical issues: incomplete schemas, missing parameter descriptions, and inadequate error handling. The code sample shows a Tool base class with some structure, but parameter definitions lack type constraints and comprehensive descriptions. Tool descriptions are present but generic (10-50 chars on average for parameters). Most critically, schema visibility is extremely limited, the source only shows partial schema inference in the tool metadata provided, not the actual JSON Schema definitions used at runtime. The bash tool presents an irreversible operation (WRITE risk classification) with minimal safety guidance. Error handling exists but is surface-level.
AI-powered code analysis, review, and explanation
AI-powered code generation, completion, and programming assistance
Generic AI provider interface for unified AI operations
AI-powered text generation, completion, and writing tasks
ai_provider tool violates single-responsibility principle: generic 'AI provider interface' is vague and does not specify what operation it performs
bash tool lacks safety guardrails and confirmation pattern for irreversible operations (WRITE risk); no dry-run support, no operation preview, no recovery guidance
Parameter descriptions are minimal: 'command' param in bash tool lacks format guidance, constraints, or unsafe operation warnings
Input schemas lack enum constraints for constrained fields: ai_code_generation 'code_type' accepts free-form strings instead of enum [function|class|algorithm|api|script]; ai_text_generation 'text_type' and 'style' are unconstrained
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 11 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 29 | - | v1 |
Output schemas not visible in source code; ToolResult structure is used but actual response fields, pagination support, and return type documentation are absent or non-standard
ai_code_generation parameter 'language' is unconstrained; LLM may hallucinate unsupported languages; should enumerate supported languages [python|javascript|java|c++|go|rust|typescript]
Error messages in code sample are generic ('Code generation error') with no recovery guidance; do not tell LLM what to do next or how to self-correct
bash tool accepts arbitrary shell commands with no input validation, sanitization, or injection prevention; poses command injection and path traversal risks
No permission gates, scope declarations, or audit trail logging visible; tools can execute without verification of caller authority