MCP server for bank data sources with AI query capabilities
Single tool with significant definition gaps. Tool is explicitly registered in mcpToolController.js with Zod schemas, but critical quality issues undermine usability: (1) Tool name 'dynamicQuery' lacks a clear action verb, 'query' is ambiguous and doesn't follow verb_noun convention (should be 'search_database' or 'query_database'); (2) Parameter descriptions are minimal and lack formatting/constraint guidance, 'language' and 'tone' are underspecified with only example values, not enums or validation rules; (3) Output schema is partially documented but response structure mixes raw data, masked summary, and AI summary without clear guidance on when/why each is present or how to interpret them; (4) No error handling guidance, code catches errors with generic `err.message` but provides no recovery hints or classification; (5) No pagination, limits, or result capping despite operating against a database, could return unbounded result sets that exhaust token budgets.
Ask any question in natural language to explore the database
Tool name 'dynamicQuery' does not start with a clear action verb and violates verb_noun convention. Should be 'query_database', 'search_database', or 'execute_query' to signal intent to LLMs.
Optional parameters 'language' and 'tone' lack proper constraints. Descriptions use only example values ('English', 'formal', 'neutral') instead of enums or validation rules. LLMs will hallucinate invalid values.
Output schema returns raw data array, masked_summary string, and ai_summary string with no documented structure or guidance on field meanings. Unclear why three separate response formats are needed or when to use each.
No pagination, limits, or result capping documented. Database queries can return unbounded result sets, risking context window exhaustion. Tool description does not warn of limits or require pagination parameters.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 35 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 26 | - | v1 |
Error handling provides no recovery guidance. Code returns generic error messages with no classification (retryable vs. fatal) or actionable next steps for LLMs.
Tool requires natural language to SQL translation via AI API but provides no security guidance on SQL injection risk, input sanitization, or how generated queries are validated before execution.
No audit logging or permission checks. Tool accepts any natural language query and executes it against the database without documenting who called it, what was queried, or what data was accessed.