Static source inference · medium confidence · evidence: Streamable HTTP
Current-spec patterns detected
Summary
Claude Workbench is a desktop/web management UI for Claude configuration, not an MCP server in the standard sense. However, it exposes 47 tools via an HTTP backend. Critical issues: (1) Most tools lack formal input schemas in the visible source code (backend/src/server.ts shows tool definitions but JSON schemas are not explicitly visible for parameter validation). (2) Descriptions exist but are extremely brief (average ~20-40 chars) and lack actionable guidance for LLM selection. (3) No output schemas documented anywhere. (4) No error handling patterns visible, no recovery guidance, no categorization of retryable vs fatal errors. (5) Many tools operate on files/config state without clear safety boundaries. (6) Parameter descriptions are minimal ('Name of the MCP server', 'ID of the profile') with no format constraints, ranges, or validation rules. (7) 9 tools handle secrets (API keys, auth tokens, environment variables) without clear secrets-injection patterns. (8) No tool annotations visible (readOnlyHint, destructiveHint, idempotentHint). The server is functionally a UI backend, not a composable agentic tool suite, tools are tightly coupled to file I/O and UI state management rather than being independently idempotent and chainable.
Tools (47)
ai_chatread onlyauth50/100
Send a message to Claude AI and get a response
clear_env_from_shell_configwrite38/100
Clear environment variables from shell configuration files
No output schemas documented for any of the 47 tools. LLMs cannot determine what fields to expect in responses, making downstream tool chaining unreliable and forcing wasteful discovery calls.
Destructive tools (delete_env_profile, delete_command, delete_skill, delete_agent, delete_project, uninstall_marketplace, uninstall_plugin) lack dry-run/confirmation patterns and no error recovery guidance. An agent deleting a critical resource has no safety net.
Add explicit JSON Schema definitions for every tool input. Include type, required/optional, min/max, enum, and pattern constraints. Example: update_claude_config.config must be object with properties {mcp_servers: array, ...}, not a bare 'object' type.
Document output schemas for all 47 tools. For get_mcp_status, specify { status: 'running'|'stopped', pid?: number, startTime?: ISO8601, logs: string[] }. For get_projects, specify { projects: [ { id, name, path, created, updated } ], total: number }.
Implement dry-run and confirmation patterns for all destructive tools. Add optional dryRun: boolean parameter to delete_env_profile, delete_project, uninstall_marketplace. Return { confirmed: boolean, action: 'deleted'|'dry-run', affectedCount: number, confirmation_token?: string } if user must confirm.
Add tool annotations to all tool definitions: readOnlyHint for read-only tools (get_*, list_*), destructiveHint for delete_* and clear_* operations, idempotentHint for tools that are safe to retry (create_*, update_* with idempotency keys).
Enhance parameter descriptions to include format constraints, ranges, and enums. Example: serverName: 'Name of the MCP server (alphanumeric + dashes, 1-64 chars, must match entry in ~/.claude.json)'. Model: 'Claude model (enum: claude-3-5-sonnet, claude-3-opus, claude-3-haiku-20250122)'.
Implement error classification and recovery guidance. When start_mcp_server fails, return { error: 'ServerNotFound', message: 'MCP server "xyz" not configured. Available servers: ["server-a", "server-b"]. Call update_claude_config to add a new server.', retryable: false, suggestedAction: 'list available servers' }.
Score history
Overall score trend
↑ 20 points across a rubric change (v1 → v2)
38/100
Scored
Grade
Overall
Spec posture
Rubric
2026-09-22
F
38
2026-07-28+
v2
2026-03-09
F
18
-
v1
destructive
45/100
Delete an AI assistant conversation
delete_env_profiledestructive45/100
Delete an environment profile
delete_projectdestructive45/100
Delete a workbench project
delete_skilldestructivesource verified45/100
Delete a skill file
expand_pathread only50/100
Expand a file path with environment variable and home directory substitution
get_agentsread only50/100
Retrieve all agents
get_ai_modelsread onlyauth50/100
Retrieve available Claude AI models from active environment profile
get_ai_toolsread only50/100
Retrieve available tool definitions for Claude AI
get_all_mcp_statusesread only50/100
Get the status of all configured MCP servers
get_claude_configread only50/100
Retrieve the Claude JSON configuration from ~/.claude.json
get_commandsread only50/100
Retrieve all custom commands
get_conversationread only50/100
Retrieve a specific AI assistant conversation
get_conversationsread only50/100
List all AI assistant conversations
get_env_profilesread only50/100
Retrieve all environment profiles from env-profiles.json
get_marketplacesread only50/100
Retrieve all installed plugin marketplaces
get_mcp_logsread only50/100
Retrieve logs for an MCP server
get_mcp_statusread only50/100
Get the current status of an MCP server
get_projectsread only50/100
Retrieve all workbench projects
get_skillsread only50/100
Retrieve all skills
get_windows_drivesread only50/100
Get list of available Windows drive letters (Windows only)
install_marketplacewrite50/100
Install a plugin marketplace from a Git repository
install_pluginwritesource verified48/100
Install a plugin from a marketplace
patch_conversationwrite47/100
Update a conversation name or project path
read_env_from_shell_configread only43/100
Read environment variables from shell configuration files (.zshrc, .bashrc, or .claude-env)
read_settings_envread only43/100
Read environment variables from settings.json
save_agentwrite50/100
Save an agent configuration
save_commandwrite50/100
Save a custom command
save_skillwrite50/100
Save a skill file
set_active_profilewrite43/100
Set the active environment profile
start_mcp_serverwritesource verified48/100
Start an MCP server process by name
stop_mcp_serverwritesource verified48/100
Stop a running MCP server process by name
uninstall_marketplacedestructive45/100
Uninstall a plugin marketplace
uninstall_plugindestructivesource verified45/100
Uninstall a plugin
update_claude_configwrite50/100
Update the Claude JSON configuration and save to ~/.claude.json
update_env_profilewrite48/100
Update an existing environment profile
update_marketplacewrite48/100
Update a plugin marketplace from its repository
update_projectwrite48/100
Update a workbench project
write_env_to_shell_configwrite40/100
Write environment variables to shell configuration files
9 tools handle secrets (write_env_to_shell_config, write_settings_env, update_claude_config, create_env_profile, update_env_profile, ai_chat with apiKey) without documented secret-injection patterns. API keys and auth tokens should never be tool parameters.
Parameter descriptions are universally terse (15-30 chars) and lack format constraints, ranges, or validation rules. E.g., 'Name of the MCP server' does not specify valid characters, length limits, or examples. No enums documented for constrained inputs (e.g., model names in ai_chat).
No tool annotations visible (readOnlyHint, destructiveHint, idempotentHint). LLMs cannot infer which tools have side effects, are read-only, or are safe to retry. This is especially critical for destructive tools like delete_* and configuration writers.
Error handling is completely absent from the visible code. No error classification, recovery guidance, or actionable error messages. An LLM calling start_mcp_server() with an invalid name gets no guidance on what to try next.
Many tools expose opaque IDs (profileId, conversationId) without accepting human-friendly identifiers (profile name, conversation title). Agents must perform extra lookup calls instead of using names directly.
No pagination support visible in list tools (get_conversations, get_projects, get_commands, get_skills, get_agents, get_marketplaces). For systems with hundreds of items, responses will be incomplete or blow the context window.
Tool definitions are inferred from sparse source code references (e.g., 'frontend/src/App.tsx') without explicit input/output schema registration visible. Cannot confirm JSON Schema compliance or parameter types for many tools.
No audit logging or permission gates visible. A tool like delete_project or write_env_to_shell_config executes with no visibility into who called it, when, or with what parameters. No least-privilege scoping.
Add human-friendly identifier support. Update delete_env_profile to accept profileName or profileId. Implement search_env_profiles(query: string) to let agents discover profiles by name before deletion.
Add pagination to all list tools. Signature: get_conversations(limit: 1-100, offset?: number, cursor?: string) -> { conversations: [...], total: number, nextCursor?: string }. Default limit=20.
Move secrets out of tool parameters. For update_claude_config, do not accept raw apiKey in the config object. Instead, provide set_env_variable('ANTHROPIC_API_KEY', value) and reference it by name in config.
Implement request-level _meta with logLevel support (per 2026-07-28 spec) for per-request logging control. Add metadata tracking: { userId, requestId, timestamp, toolName, parameters (sanitized) } for audit trails.
Add tool idempotency. create_project with the same name should return the existing project (via idempotencyKey in response) rather than erroring. This enables safe agent retry.
Document which tools require file-system access and operating system. get_windows_drives is Windows-only; read_env_from_shell_config differs on macOS/Linux. Add platform constraints to descriptions.
Create a discovery tool: list_all_tools() returning { tools: [ { name, description, params, riskLevel } ] }. Agents can call this once to bootstrap tool knowledge instead of relying on LLM hallucination.
Add permissioning. Each tool should declare required scopes (e.g., delete_project requires 'projects:delete', write_env_to_shell_config requires 'env:write'). Verify agent has scope before execution.