Lightweight AI agent framework with memory, tools & tree-of-thought. Supports multi-agent collaboration, self-learning, and major LLMs (OpenAI/DeepSeek/Qwen). Open-source with MCP/SSE protocol integration.
LightAgent exhibits significant quality gaps across naming, descriptions, and schema documentation. While 11 tools are defined, most lack adequate descriptions (5 of 11 have <50 chars), parameter schemas are minimal or missing, and output structures are undocumented. The server mixes Chinese and English descriptions inconsistently. Several tools expose dangerous capabilities (execute_python_code, upload_file_to_oss) without clear security guidance. No error handling patterns are visible. Tool composition is poor, multiple tools do similar things (get_weather appears twice with different names), and execute_* tools lack the safety constraints needed for production use. This is a 'D' grade server, poor foundational quality with major issues.
加载指定技能的完整指令到上下文
Calculate bmi given weight in kg and height in meters
Safely execute Python code with sandboxing and import restrictions
Execute Python code and stream the output
Execute a Python script file with sandboxing and import restrictions
执行技能目录scripts/下的脚本文件
Fetch current weather for a city
Multiple tools serve identical or overlapping purposes without clear disambiguation. 'fetch_weather' and 'get_weather' both retrieve weather with no documented difference. LLMs will waste reasoning cycles choosing between them.
Code execution tools (execute_python_code, execute_python_file, execute_python_code_stream) lack comprehensive security documentation. Descriptions claim 'sandboxing' but do not explain constraints, allowed imports, timeout limits, or failure modes. Agents cannot assess risk or plan for failure.
No output schemas documented for any tool. LLMs cannot infer response structure, required downstream IDs, or pagination patterns. Responses appear to be unstructured strings (e.g., JSON strings returned by list_skills and skill_tools) rather than structured objects.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 42 | 1.9.0+ | v1 |
获取指定地区的天气信息
获取所有已加载技能的列表及其描述
读取技能目录references/下的文档内容
将本地文件上传到阿里云OSS,自动使用MD5重命名文件,支持设置公共读权限
Tool descriptions are too brief or generic. 'Fetch current weather for a city' (35 chars) and 'Execute Python code with sandboxing and import restrictions' (60 chars) do not explain when to use each tool, what happens on error, what sandboxing constraints apply, or which fields are returned. Descriptions should be 100-200 chars and include dependency hints.
Inconsistent language mixing. Tool descriptions are in Chinese (e.g., '获取所有已加载技能的列表及其描述') while others are in English. This inconsistency causes confusion in multilingual LLM contexts and violates naming convention stability.
No error handling guidance. Tools do not document what errors are possible, how to recover, or what the LLM should do if a call fails. For example, execute_skill_script returns 'skill_manager.execute_script(...)' with no documented exception handling, return format, or failure classification.
Parameter descriptions are sparse or missing context. 'args' in execute_skill_script is described only as '脚本参数列表' with no format, length limits, or examples. 'code' in execute_python_code has no description of allowed imports, blacklist, or execution environment.
upload_file_to_oss exposes cloud credentials and behavior without security documentation. Lacks explanation of file naming (MD5 rename mentioned only in description), permission model (public read mentioned inline), failure scenarios, and retry logic. Agents cannot assess cost, blast radius, or side effects.