Code analysis MCP server for repository structure analysis and file reading
Two tools with basic descriptions and partially visible schemas. analyze_repository has a clear description (81 chars) and defined input parameters (repo_path, max_depth), but output schema is not documented in the provided code. read_file has a basic description (93 chars) and clear inputs (repo_path, file_path), but no output schema visible. Neither tool has documented return types or error handling guidance. Parameter descriptions are present and adequate (repo_path, file_path, max_depth), meeting baseline minimums. However, there is no evidence of schema validation, error categorization, or recovery guidance in the source code. Both tools operate in a read-only context (no destructive operations), which reduces security risks. The code shows path validation logic (_is_safe_path, symlink checks, gitignore handling) but these defensive checks are not surfaced in tool descriptions to guide the LLM.
Analyze the repository structure and return a tree-like overview of files and directories
Read the contents of a file from the repository with syntax highlighting support
Output schemas not documented. Neither analyze_repository nor read_file declares what fields/types are returned. LLMs cannot plan downstream tool calls or extract required data without knowing the response structure.
No error handling guidance. Code performs path validation (_is_safe_path, gitignore checks) but tools do not describe what errors are possible, when they occur, or how the LLM should recover. E.g., what happens if repo_path is invalid? What if file_path traverses outside the repo?
No input validation constraints in descriptions. max_depth parameter lacks bounds (e.g., 'must be 1-10'). Neither tool describes file size limits (FileReader.MAX_SIZE = 1MB, MAX_LINES = 1000) or what happens when files exceed limits.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 14 | - | v1 |
Incomplete parameter descriptions. max_depth says 'Maximum depth of directory traversal (default: 3)' but does not state the minimum or maximum allowed value, or what happens if depth is exceeded (summary vs. full children list).
Tool composition missing. No discovery/enumeration tool to list available repositories or validate a path before attempting analysis. Agents must guess repo_path values.