AIIR forensic investigation platform — SIFT workstation monorepo containing multiple MCP servers for incident response, case management, forensic analysis, and threat intelligence
Scoring was not performed
Output schemas are not documented. LLMs cannot plan downstream operations or know what fields to expect from search results, source lists, or statistics.
No error handling guidance in tool descriptions. If a search returns no results or if an invalid MITRE technique ID is provided, there is no documented recovery path or error classification.
Descriptions for list_knowledge_sources and get_knowledge_stats are under 100 characters and lack guidance on WHEN to call these discovery tools relative to search_knowledge.
Parameter interdependency between 'source' and 'source_ids' is documented in search_knowledge ('Takes precedence over source'), but this relationship is not explicitly stated in both parameter descriptions as a mutual constraint.
The search_knowledge tool lacks guidance on output pagination or result limits. The description mentions 'top_k' (max 50) but does not explain what happens if more than 50 relevant results exist or how agents should handle partial results.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 0 | 2026-07-28+ | v2 |
| 2026-03-09 | C | 61 | - | v1 |