This is a broad kitchen-sink server with 34 tools covering BookStack, Context7, Coolify, DuckDuckGo, Excel, file operations, and Firefly. While tool schemas ARE present and descriptions are provided, there are significant consistency and quality gaps. Most tools have acceptable (10-80 char) descriptions, but several lack necessary parameter documentation, optional/required clarity, and output schema specifications. The server follows basic registration patterns but falls short on LLM optimization and guidance clarity. Tool naming is generally verb-forward and clear (list_*, get_*, search_*), which is a strength. However, many parameters lack descriptions or type clarity, and error handling guidance is minimal. No tool annotations (readOnlyHint, destructiveHint, idempotentHint) are declared despite clear read/write distinctions in the feature summary. The composition is reasonable for discovery, but several tools could be merged or split for better agent ergonomics.
Get details for a single BookStack book by ID.
Get a single BookStack page by ID (returns page content).
Get details for a single BookStack shelf by ID.
List all books in BookStack.
List pages. Optional limit parameter.
List all bookshelves in BookStack.
Transport is STDIO only, not remotely accessible. Hosted MCP clients cannot connect to this server.
Missing output schemas and return type documentation. LLMs cannot plan downstream tool calls or extract fields without knowing what the response structure is.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint) declared despite clear risk classifications (READ_ONLY vs WRITE). LLMs cannot determine tool safety without explicit hints.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 56 | 2025-06-18+ | v2 |
| 2026-03-09 | F | 46 | - | v1 |
Search BookStack using the query string.
List all applications/deployments in Coolify.
Get deployment status for an application by deployment ID.
Fetch build/deployment logs for an application.
Get details for a single Coolify server by ID.
List all servers registered in Coolify with their IP, user, port, reachability, and validation status.
Check if Coolify API is reachable and responding.
Trigger a new deployment for an application. Optionally specify the git branch to deploy.
Search DuckDuckGo and get results (no API key required). Returns instant answers and related topics.
Read a worksheet range from a local Excel workbook and return the values as JSON rows.
Inspect workbook metadata, sheet names, and sheet dimensions for a local Excel file.
Write a 2D value matrix into a local Excel workbook, creating the file or sheet if needed.
Get details for a single account by ID.
Get a single budget by ID.
Get a basic account summary.
Get a single transaction by ID.
List all accounts from Firefly.
List budgets.
List all categories.
List transactions with optional paging or date range.
Fetch comprehensive documentation for a library from Context7. Supports optional topic focus to get more specific documentation.
List files in a directory with optional glob pattern and recursive search
Discover registered tools by scanning compiled tool files in dist/tools
Read the contents of a file with security validation
Find the correct Context7 library ID for a package, framework, or library. Returns the best matching library with metadata.
Search across multiple libraries in Context7 for documentation related to a specific topic or concept.
Get current security configuration and validation status
Write content to a file with security validation
Pagination not implemented. List tools (bookstack_list_*, coolify_get_applications, firefly_list_*, etc.) lack limit/offset or cursor parameters, risking context window overflow.
Error handling lacks recovery guidance. bookStackFetch() throws generic 'BookStack API error' messages without suggesting alternative tools or next steps.
Parameter descriptions are minimal or vague. 'Max results (optional)' in bookstack_list_pages and 'optional limit parameter' lack specificity on range, default, or units.
security_status tool has no documented output schema. The description says 'Get current security configuration' but does not specify the return structure.
API credentials (BOOKSTACK_TOKEN_ID, BOOKSTACK_TOKEN_SECRET, etc.) are loaded from environment and not exposed as parameters, this is correct. However, no documented validation that credentials are set before tool invocation.
mcp_tools_discovery tool description is vague: 'Discover registered tools by scanning compiled tool files in dist/tools', does not explain when an LLM should call this vs relying on the MCP tools list.