MCP server for agent automation: persistent memory and deterministic workflow execution for AI agents and chats
The Kairos MCP server defines 8 tools with complete input schemas and non-empty descriptions. Tool names follow verb_noun conventions (activate, forward, train, reward, tune, delete, export, spaces). However, several tools have descriptions that are too terse (10-30 chars) to guide LLM selection effectively. Parameter descriptions are present but often lack detail on constraints, expected formats, and valid value ranges. Output schemas are not documented in the provided source. Error handling guidance is absent, tools do not indicate what the LLM should do if a call fails. Security considerations around credential handling are not evident in the tool definitions. The server demonstrates moderate definition quality with room for improvement in description richness, constraint documentation, and error recovery guidance.
Find the best adapter for the current input and return ranked activation choices.
Delete an adapter or layer by URI.
Export adapter markdown or training datasets.
Run the first or next adapter layer. Omit `solution` on the first call in a run.
Attach a reward signal after adapter execution completes.
List the agent's available spaces with human-readable names and adapter counts. Optionally include adapter titles and layer counts per space.
Output schemas not documented. LLMs cannot plan downstream tool calls or extract required fields from responses. Tools like 'activate' return 'ranked activation choices' but the structure (fields, types, pagination) is not specified.
Descriptions for several tools are terse and lack guidance on WHEN to use them or WHY over alternatives. 'forward' (50 chars), 'tune' (35 chars), and 'delete' (35 chars) descriptions do not explain prerequisites, expected inputs, or side effects.
Parameter descriptions lack constraint details. 'max_choices' has no min/max bounds. 'llm_model_id' has no format hints. 'space' and 'space_id' parameters offer no guidance on valid values or how to obtain them.
Inferred effective spec: 2025-06-18+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 63 | 2025-06-18+ | v2 |
| 2026-03-09 | D | 53 | - | v1 |
Store a new adapter from markdown.
Update adapter layer content.
No error handling guidance. Tools like 'delete' (DESTRUCTIVE) and 'forward' (WRITE) do not document what errors might occur, when they are retryable, or how the LLM should recover. No confirmation or dry-run option for irreversible operations.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint) declared in tool definitions. The Risk field is labeled in the evaluation but not visible as formal schema annotations. This prevents MCP clients from applying appropriate safeguards.
Parameter 'solution' in 'forward' tool is described as 'Optional on continuation calls; omit on start' but this temporal dependency is not enforced in the schema. LLMs may pass or omit it unpredictably. Document stateful behavior clearly or redesign to avoid it.
'delete' tool lacks confirmation or dry-run safety. A destructive operation with only a URI parameter and no confirmation step invites accidental data loss. Per pattern:confirmation-request, irreversible operations should support a confirm_before_execute pattern.