MCP server for Linkerd2 service mesh context, providing mesh graph queries and authorization policy management via gRPC
This server has critical gaps in tool definition quality. While 2 tools are present with declared names and descriptions, the input schemas lack proper JSON Schema structure with type definitions. Tool descriptions are present but minimal (86-161 characters), and parameter descriptions are either missing or extremely limited. The GetMeshGraph tool accepts an empty input object with no parameters. The ApplyAuthorizationPolicy tool has parameters with type declarations but no descriptions for individual parameters. Output schemas are not documented. This falls far below production-grade standards for LLM-driven tool selection and usage.
Apply or update an authorization policy in the mesh graph and publish the delta to Redis for cluster reconciliation
Retrieve the complete mesh graph including services, edges, and authorization policies
GetMeshGraph has completely empty input schema ({}). No parameters are defined, no schema validation possible. Cannot validate LLM invocations.
ApplyAuthorizationPolicy parameters (namespace, name, json_spec) lack individual parameter descriptions. LLM cannot understand what each field controls, its constraints, or why it is required. JSON schema shows types but descriptions are essential for LLM reasoning.
No output schemas documented for either tool. LLMs cannot plan downstream calls or extract needed fields. GetMeshGraph should document the structure of the mesh graph (services, edges, auth policies). ApplyAuthorizationPolicy should document what is returned (success, delta, updated graph state).
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 10 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 28 | - | v1 |
Tool descriptions are too minimal (86 and 161 characters, below the production baseline of 194 chars avg). GetMeshGraph's description does not explain WHEN to call it or what decisions it enables. ApplyAuthorizationPolicy description does not specify prerequisites, side effects (Redis publication), or failure modes.
ApplyAuthorizationPolicy's 'json_spec' parameter is dangerously open-ended. Description says 'JSON specification' but provides no schema, constraints, or example structure. LLM will hallucinate invalid JSON. Should define the exact required fields, validation rules, and format.
No error handling guidance in either tool description. ApplyAuthorizationPolicy is a WRITE operation that publishes to Redis, failure modes (invalid spec, namespace not found, Redis unavailable) and recovery steps are not documented. LLM has no way to decide if it should retry.
No distinction between read-only and write tools in the tool registration. ApplyAuthorizationPolicy is marked WRITE in metadata but tool description does not explicitly state it modifies state and has irreversible consequences. LLM may not recognize the risk.