A general-purpose, secure Model Context Protocol (MCP) server for MySQL databases.
Single read-only query tool with basic definition. Tool naming is reasonable (read_only_query is action-oriented), but description and schema have critical gaps. The description is adequate (89 chars, within baseline range), but the schema is severely incomplete: it uses a raw Zod object without proper JSON Schema structure or type declarations visible in the schema definition. Parameter 'sql' lacks detail on format, constraints, or what constitutes a valid query beyond the SELECT prefix check. No output schema is documented, responses are returned as raw JSON strings without type information. Error handling is minimal: only two cases checked (non-SELECT prefix, database error), with generic error messages that don't guide recovery. Resource 'schema' is present but not assessed as a tool per the rubric.
Executes a read-only SQL query (MUST start with 'SELECT') on the database.
Input schema is incomplete. Parameter 'sql' has no type constraint, min/max length, regex pattern, or format documentation. Zod schema is used but not serialized to JSON Schema format visible in the code.
Output schema is not documented. Tool returns raw JSON strings with no type annotation or structured format description. LLM cannot reason about response structure or extract fields reliably.
Parameter description lacks format and constraint detail. 'sql' param only states 'The SQL SELECT statement to execute' but doesn't specify: max query length, allowed/disallowed keywords (JOIN, subquery depth, etc.), or whether multiple statements are supported.
Error messages are generic and non-actionable. 'Only SELECT queries are permitted' and 'Database query failed: <message>' don't guide the LLM on recovery steps. No error categorization (retryable vs fatal).
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 50 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 39 | - | v1 |
Tool description does not document result limits or pagination. If a SELECT returns thousands of rows, the response will be a massive JSON string that blows context windows. No mention of limiting behavior.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint). Although the tool is marked risk=READ_ONLY in metadata, this is not surfaced via tool annotations in the MCP protocol.