Mixed quality across 13 tools. Strong points: all tools have descriptions (in German), schemas use Zod with basic types, and security measures are present (path traversal checks, SQL keyword blocking). Critical gaps: descriptions are uniformly short (10-50 chars), lacking context on WHEN to use each tool or WHAT it returns; parameter descriptions are minimal; no output schemas documented; error messages lack recovery guidance; no idempotency hints on write operations; annotations present but inconsistently applied (write_file has destructiveHint=false which is incorrect). Tools are functional but fall short of production-grade documentation and error handling expected for agent use.
Fügt Datensätze in eine Tabelle ein
Liest Daten aus einer Tabelle mit optionalen Filtern
Führt rohe SQL via RPC execute_sql aus. Gefährliche Befehle sind blockiert.
Aktualisiert Datensätze in einer Tabelle. Filter ist Pflicht.
Insert oder Update (Upsert)
Listet Dateien in einem Repository auf
Listet alle verfügbaren Repositories auf
Descriptions are critically short (10-50 chars), violating baseline of 194 chars average. Most tools lack WHEN to use context, recovery hints, or expected output structure. Example: 'Liest Dateien in einem Repository auf' (42 chars) tells LLM nothing about default patterns, return format, or when to call list_repos first.
No documented output schemas. Tools return content arrays, but LLMs do not know what fields to expect in responses (e.g., does n8n_get_execution return execution status, start time, end time, logs?). Without schema documentation, agents cannot plan chaining calls or extract relevant data.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 47 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 51 | - | v1 |
Liest Details zu einer n8n Execution per ID
Liest einen einzelnen n8n Workflow per ID
Listet n8n Executions, optional gefiltert nach Workflow und Status
Listet n8n Workflows über die lokale/self-hosted n8n API auf
Liest den Inhalt einer Datei aus einem Repository
Schreibt Inhalt in eine Datei eines Repositories
Parameter descriptions are missing or generic. Example: db_query accepts 'filter' (object type) with no description of filter syntax, allowed operators, or nested field support. n8n_list_executions 'status' enum documented but 'workflowId' lacks context on format or whether it accepts names or IDs only.
Error handling does not guide recovery. Code shows security checks (resolveRepoPath, checkSqlSafety) that throw Error(), but error messages are generic ('Pfad außerhalb des Repos nicht erlaubt'). No guidance: 'Try removing ../ from path' or 'Repo paths must be relative to root.'
write_file annotation has destructiveHint: false, which is INCORRECT. This tool writes/overwrites files (high destructive risk). Should be destructiveHint: true. Agents rely on this hint to apply caution.
Database write tools (db_insert, db_update, db_upsert, db_raw_sql) lack idempotency or confirmation hints. No indication whether repeated calls with same data cause duplicates, updates, or errors. Agents will not know if it's safe to retry on network timeout.
db_raw_sql blocks some SQL keywords but approach is incomplete. Blocklist includes 'DROP TABLE' but not 'DROP COLUMN', 'TRUNCATE', or 'DELETE FROM'. A motivated attacker can bypass with 'DELETE FROM table WHERE 1=1'. Also, no audit logging of SQL queries for compliance.
Database parameters (table, filter, on_conflict) accept free-form strings, inviting SQL injection via LLM-provided input. For example, db_query with filter={"name": "'; DROP TABLE users;"} could succeed if client-side validation is weak. No evidence of prepared statements or parameterized queries in visible code.
list_files and list_repos return raw JSON dumps without structured field definitions. LLMs do not know if returned object keys are stable across versions or what each field means.
German descriptions conflict with English-speaking LLM ecosystems. Tools are documented entirely in German, which limits LLM understanding if model weights emphasize English. Should provide English descriptions or dual-language support.