File storage and sandbox backends for AI agents
This server exposes 6 tools with basic HTTP transport via FastAPI. However, critical quality gaps significantly limit production readiness. Tool descriptions are present but minimal (13-36 characters on average, well below the 50-200 character baseline). Parameter descriptions are similarly sparse, providing little context for LLM tool selection. Critically, several high-risk tools (execute, write, end_session) lack proper error handling guidance, security scoping, and confirmation patterns. No input validation constraints are visible (enums, patterns, ranges). Output schemas are not documented. Tool naming is clear and verb-based, which is a strength, but the overall assessment is pulled down by missing schema completeness, absent parameter validation metadata, and lack of error recovery guidance for destructive operations.
Create a new isolated session for a user
End a user session and cleanup resources
Execute a command in the user's sandbox
List files in the user's workspace
Read a file from the user's workspace
Write a file to the user's workspace
Destructive operations (write, execute, end_session) lack confirmation/dry-run patterns and clear irreversibility warnings in descriptions
No output schemas documented for any tool. LLMs cannot plan downstream calls or extract structured data from responses.
Tool descriptions are too brief (<20-50 chars). Descriptions like 'Read a file from the user's workspace' lack guidance on WHEN to use the tool vs similar ones, prerequisites, or return expectations.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 65 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 31 | - | v1 |
No input validation constraints visible: no enums for required categorical parameters, no min/max bounds for timeout/path parameters, no regex patterns or length limits.
Error handling patterns missing. No guidance on retryability, user-fixable vs fatal errors, or recovery steps for common failures (file not found, command timeout, permission denied).
Session-based design (session_id parameter) may leak statefulness into requests. Modern MCP protocol is stateless; session context should be handled server-side or injected via tool gateway, not exposed as a parameter.
No security scopes or permission declarations visible. Tools that modify filesystem or execute commands should declare required permissions (read:workspace, write:workspace, exec:sandbox).
Parameter descriptions are minimal or missing detail on constraints. E.g., 'timeout' parameter for execute has default=30 but no description of unit (seconds assumed), min/max bounds, or behavior on timeout.