MCP server for the Oberon 360 ecosystem by TSI (Thomas Seguridad Integral). Provides dynamic configuration and management of security modules, users, clients, roles, permissions, and advanced data filtering for the intelligent security operations platform.
MCP-OBERON is a moderately well-structured server with 14 tools for an Oberon ERP system. Tool naming follows verb_noun conventions (Obtener_, Buscar_, Crear_, Verificar_), which is good. Descriptions are present for all tools and generally informative (150-300 chars), but lack actionable guidance on WHEN to use each tool vs. alternatives. Schemas are well-defined with proper types, enums, and defaults. However, output schemas are not documented, the rubric requires tools to document what fields they return (e.g., 'Obtener_Clientes returns JSON parseable in field text' is vague; should specify fields like id, name, role, zone, locations). Error handling is minimal, tools do not guide recovery (e.g., no guidance on what to do if a search returns 0 results). Security is reasonable (token passed server-side), but tools lack explicit permission declarations. Tool composition is fragmented, separate 'Obtener_Clientes', 'Obtener_Cliente_por_ID', and 'Buscar_Registros_De_Funcionalidad' exist, but the LLM instructions compensate for this fragmentation via the systemPrompt, which is not scalable. Parameter descriptions are adequate but could be more precise (e.g., 'terminoBusqueda' lacks format guidance).
Busca y devuelve la definición de una ÚNICA funcionalidad que coincida con el nombre proporcionado. Es la forma más rápida de obtener el ID y la estructura de campos.
Busca registros dentro de una funcionalidad específica usando filtros avanzados JSON. Soporta operadores complejos (equals, contains, between, gte, lte, gt, lt) y operadores lógicos ($and, $or, $not). Maneja automáticamente conversión de títulos de campos a IDs internos y filtrado de fechas en el cliente si es necesario. Si exportToExcel=true, genera un archivo Excel descargable.
Crea un nuevo usuario en el sistema Oberon con los parámetros especificados.
Busca y devuelve un cliente del sistema, incluyendo su rol, zona y ubicaciones. Devuelve datos en formato JSON parseable en el campo 'text'.
Busca y devuelve una lista detallada de clientes del sistema, incluyendo su rol, zona y ubicaciones. Devuelve datos en formato JSON parseable en el campo 'text'.
Output schemas are not documented. Tools return JSON in 'text' field but the structure (fields, types) is not specified. LLMs cannot plan downstream calls or extract data reliably without knowing response structure.
Error handling is absent. Tools do not provide recovery guidance (e.g., 'If search returns 0 results, try with a broader term' or 'If placa not found, verify it is registered in GPS system'). Agents have no guidance on retrying or alternatives.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | <=2025-11-25 | v2 |
| 2026-03-09 | D | 59 | - | v1 |
Busca y devuelve DEFINICIONES de funcionalidades (admin) usando un filtro JSON complejo. Útil para búsquedas avanzadas con múltiples condiciones. Devuelve datos en formato JSON parseable en el campo 'text'. Si exportToExcel=true, genera un archivo Excel descargable en /assets/ con timestamp.
Busca y devuelve un permiso del sistema dado su ID. Devuelve datos en formato JSON parseable en el campo 'text'.
Busca y devuelve una lista detallada de permisos de módulo del sistema. Devuelve datos en formato JSON parseable en el campo 'text'.
Busca y devuelve un rol del sistema dado su ID. Devuelve datos en formato JSON parseable en el campo 'text'.
Busca y devuelve una lista detallada de roles del sistema. Devuelve datos en formato JSON parseable en el campo 'text'.
Busca y devuelve un usuario específico del sistema por su ID.
Busca y devuelve una lista de usuarios del sistema. Es la herramienta principal para búsquedas de usuarios por nombre, correo, email o username.
Verifica el estado y ubicación GPS de un vehículo usando su placa. Devuelve datos de ubicación en tiempo real si el vehículo está registrado e integrado.
Verifica el estado de temperatura de un vehículo usando su placa. Devuelve datos de temperatura en tiempo real si el vehículo está registrado e integrado.
Descriptions lack WHEN and WHY guidance. 'Busca y devuelve una lista...' explains WHAT but not WHEN to use this tool vs. 'Obtener_Clientes'. Descriptions should guide tool selection for LLMs choosing between similar tools.
Parameter 'filtro' in Buscar_Registros_De_Funcionalidad lacks format examples and validation rules. Description mentions JSON with operators but does not specify: What are valid operators? What fields can be filtered? What date format is expected? LLMs will struggle to construct valid filters.
Tool 'Crear_Usuario' has no confirmation or dry-run support. Creating users is irreversible; agents should be able to preview what will be created before committing. Currently agents can accidentally create duplicate users without safeguards.
Tool naming 'Verificar_Estado_GPS_Placa' and 'Verificar_Estado_Temperatura_Placa' are somewhat ambiguous. 'Verificar_Estado' could mean 'check status' or 'verify it is working'. Consider renaming to 'get_vehicle_gps_location' and 'get_vehicle_temperature' for clarity.
No explicit permission declarations on tools. Tools should declare what scopes they require (e.g., 'read:clients', 'write:users', 'read:gps'). This prevents overprivileged agent tokens and aids audit trails.