Elastic Fleet Integration Package metadata MCP server. Provides tools to search and query integration package metadata, documentation, changelogs, security rules, and ECS field definitions via SQL and full-text search.
fleetpkg-mcp demonstrates solid definition quality with clear, well-structured tool names, comprehensive descriptions, and documented input schemas. All 7 tools follow verb_noun naming conventions (get_, execute_, search_, match_). Descriptions are detailed and explain WHAT, WHEN, and prerequisites clearly. Input parameters are well-typed with descriptions. However, output schemas are not explicitly documented in the source code, and error handling guidance is missing, these gaps prevent a higher score. The server targets domain experts (security analysts, package maintainers) with reasonable parameter constraints and helpful discovery patterns (e.g., 'Call this tool first!').
Call this tool to execute an arbitrary SQLite query. Be sure you have called fleetpkg_get_sql_tables() first to understand the structure of the data!
Call this tool first! Returns the complete catalog of available tables and columns.
Check whether field names exist in ECS (Elastic Common Schema). Given a list of dotted field names, returns each annotated with is_ecs (bool), and for matches: ecs_data_type and ecs_description. Use this to identify which package fields should use "external: ecs" to inherit the upstream ECS definition.
Full-text search across package changelog entries. Uses FTS5 with porter stemming — supports phrases ("fix bug"), prefix (SSL*), and boolean operators (AND/OR/NOT). Returns matching changelog entries with package name, version, change type, description, and link, sorted by relevance.
Full-text search across package documentation (READMEs, guides, knowledge base articles). Uses FTS5 with porter stemming — supports phrases ("log rotation"), prefix (authent*), and boolean operators (AND/OR/NOT). Returns matching doc snippets with package name, doc type, and file path, sorted by relevance.
Output schemas are not formally documented. All 7 tools describe their return fields narratively in descriptions, but no explicit JSON Schema output types are visible in source. This forces LLMs to infer return structure and risks misalignment on field names, types, and nesting.
Error handling guidance is missing. Tools that call external SQL queries or FTS5 searches (fleetpkg_execute_sql_query, all search_* tools) do not document what happens on malformed input, timeout, or database errors. No recovery hints provided (e.g., 'If syntax error, try simplifying the query').
Inferred effective spec: 2026-07-28+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 70 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 16 | - | v1 |
Full-text search across ECS (Elastic Common Schema) field definitions. Use this to discover ECS fields related to a concept. Accepts plain keywords, dotted field names, or camelCase identifiers — the query is automatically normalized (dots and camelCase are split into tokens, plain terms are OR-joined for broad discovery). Example: "crowdstrike.fdr.ProcessTTYAttached" finds process.tty and related fields. Also supports FTS5 syntax when needed: phrases ("source address"), prefix (authent*), and boolean operators (network AND bytes). Returns matching fields with name, data_type, description, is_array, and pattern, sorted by relevance.
Full-text search across security detection rules (title, description, query, setup guide, investigation note). Uses FTS5 with porter stemming — supports phrases ("credential access"), prefix (powershell*), and boolean operators (AND/OR/NOT). Returns matching rules with package name, rule ID, type, severity, risk score, title, and description, sorted by relevance.
Parameter constraints are incomplete. Several string parameters (query in search_* tools, statement in execute_sql_query) lack explicit length limits, valid value ranges, or character restrictions. FTS5 query syntax is described narratively but not formalized as a pattern or enum.
Pagination not explicitly documented. search_* tools accept 'limit' parameters (default 20) but do not document whether results are sorted, what happens when limit is exceeded, whether a cursor/offset for next-page retrieval is provided, or total count. For search_docs and search_changelogs with potentially large result sets, pagination guidance is critical.