A Model Context Protocol server for executing SQL queries across multiple database types with Groovy script extensions for data processing
This MCP server has critical gaps in definition quality. While 3 tools are defined, two have acceptable descriptions but their input schemas are only partially visible in the provided code. The tool 'executeSqlOnDefault' uses string-based SQL execution without constraints or safety validation hints in the schema. Parameter descriptions are minimal (1-2 words). No output schemas are documented. The server exposes a WRITE risk tool (executeSql) without clear error handling, confirmation patterns, or security-focused descriptions. Tool names follow verb_noun convention, which is positive, but descriptions lack depth about when to use each tool and what to expect. Overall, definitions are sparse and lack the rigor needed for reliable LLM-based tool selection.
Execute a Groovy script extension for data processing and transformation
Execute SQL on the default data source (%s database)
List all available Groovy script extensions with their descriptions and parameters
WRITE-risk tool (executeSqlOnDefault) lacks security and side-effect warnings in description. LLMs cannot determine if a tool call is reversible or has destructive consequences.
No output schemas documented for any tool. LLMs lack visibility into return types and cannot reliably plan downstream calls or extract needed fields.
Parameter descriptions are under 20 characters for most parameters ('SQL query to execute', 'Input data to process'). Lack detail on format, constraints, or expected structure.
No error handling guidance in any tool description. LLMs do not know what errors are possible, whether they are retryable, or what corrective action to take.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 45 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 39 | - | v1 |
listAvailableExtensions has no documented output schema. Agents cannot discover available extension names and must rely on hardcoded knowledge.
No input validation constraints or enums visible. extensionName accepts any string; executeSqlOnDefault accepts any SQL string. LLMs will hallucinate invalid values.
No permission checks, scope declarations, or audit trail logging visible. A destructive tool like executeSql must verify the caller has write permission before executing.