Collection of MCP server setup scripts and utilities for managing multiple database systems (MySQL, MongoDB, DynamoDB, Redshift, Redis) on AWS infrastructure
This MCP server exhibits severe definition quality issues across all dimensions. Tool names lack clarity and proper verb-noun structure. Descriptions are present but often generic and fail to communicate irreversibility and prerequisites. Input schemas are partially visible but lack proper type definitions for most parameters. No documented output schemas. No error handling guidance. Security practices are critically flawed, credentials are passed as parameters rather than injected server-side. The codebase appears to be bash/Python scripts for AWS RDS/database operations, but tool definitions are not formally registered with proper MCP metadata. Only 6 tools are nominally defined, but actual MCP registration code is not visible in the provided source.
Inserts test data into Aurora MySQL database using RDS Data API (creates customers, products, orders tables and populates with sample data)
Creates RDS MySQL 8.0.41 instance with specified configuration (Single-AZ, db.t3.medium, 50GB gp3 storage, no public access)
Creates RDS MySQL 8.0.41 instance in China (Ningxia) region cn-northwest-1 with same configuration as standard instance
Inserts test data into RDS MySQL database (creates customers, products, orders tables with sample data via pymysql)
Resets existing tables and inserts comprehensive sample data into MySQL 'mcp' database (persons, customers, products, orders, order_items tables)
Configures and starts MCP servers for multiple databases (MySQL, MongoDB, DynamoDB, Redshift, Redis) with environment variable-based credentials
Credentials passed as tool parameters instead of server-side injection. Tools expose MYSQL_PASS, AWS_SECRET_ACCESS_KEY, and database passwords as parameters. These will be logged in agent traces, violating security baseline.
No input schemas visible for parameters. Tools declare parameters (MYSQL_HOST, master_password, etc.) but no JSON Schema type definitions are present in the provided source.
Irreversible operations (WRITE, DESTRUCTIVE, IRREVERSIBLE risk labels) lack dry-run or confirmation mechanisms. reset_and_insert_data explicitly drops and recreates tables with no undo option.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 29 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
No output schemas documented. Tools do not declare what they return (success confirmation, created resource IDs, error details). Agents cannot plan downstream actions.
Naming lacks verb-noun clarity. 'setup_mcp_database_servers' (29 chars, exceeds p90=27) uses 'setup' which is vague. 'reset_and_insert_data' contains 'and', signaling multiple responsibilities (reset table structure + insert sample data). Should split into 'reset_database_tables' and 'insert_sample_data'.
Parameter descriptions are minimal or missing context. 'Master password for RDS instance (prompted at runtime)' does not explain password requirements (length, character set, restrictions). 'MySQL host endpoint' does not clarify format (FQDN vs IP).
No error handling guidance. Bash scripts use 'echo' for errors but do not categorize them (retryable vs fatal) or provide recovery suggestions. An agent encountering 'Creating DB subnet group...' has no signal to retry or escalate.
Tool definitions not formally registered via MCP protocol. Source code shows bash/Python scripts but no explicit tool registration with MCP metadata (names, descriptions, input/output schemas in MCP format).
No permission gates. Tools allow AWS RDS instance creation and database reset without checking caller authorization. A compromised agent can destroy production data or rack up AWS bills.
No audit logging. Scripts do not log who invoked them, what parameters were passed, or what happened. Compliance and incident response are impossible.