Auth proxy and aggregator for Model Context Protocol servers
mcp-front is a reverse proxy/auth gateway for MCP servers, not a traditional MCP tool server. The 4 test tools (echo_text, sample_stream, get_time, echo_streamable) are mock fixtures in JavaScript, not actual production tools. All 4 tools have minimal, generic descriptions (7-26 chars) far below the 34-char p10 baseline. None have parameter descriptions. Schemas are present but trivial, most parameters are optional or empty. The server's primary function is proxying and authenticating requests to upstream MCP servers, not providing domain-specific tools. Tool definitions appear in mock test fixtures (mock-sse-server.js, mock-streamable-server.js), not in the Go application code. This is a protocol implementation test harness, not a tool-rich MCP server.
Echo text back
Echo the provided text
Get the current time
Sample streaming tool
All tool descriptions are critically short (7-26 chars), far below the 34-char baseline minimum. 'Echo the provided text' (26 chars) fails to explain when to use this tool, what it returns, or distinguish it from echo_streamable.
No parameter descriptions. The 'text' parameter in echo_text and echo_streamable lacks any description explaining what text format is expected, constraints, or examples.
sample_stream and get_time have empty inputSchema properties ({}), meaning they accept no parameters. Schemas are technically valid but uninformative, no indication of output schema or what the stream contains.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 39 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 32 | 2025-11-25+ | v1 |
No output schema documentation. None of the 4 tools document what fields/structure they return. LLMs cannot plan downstream calls without knowing output shape.
Tool definitions are in mock test fixtures (JavaScript files), not in the main Go application. This makes it ambiguous whether these are intentional production tools or test stubs. The server's actual purpose is reverse-proxying auth for upstream MCP servers, not providing these 4 tools.
No error handling guidance. Mock server returns JSON-RPC errors (code -32601 for unknown tools) but no actionable recovery hints.