An MCP server that generates and manages dummy e-commerce sales data, providing tools and resources for products, users, and categories in a MySQL database.
This server has critical gaps across all dimensions. While three tools are defined with basic schemas and descriptions, the definitions are generic, lack parameter details critical for LLM decision-making, and the codebase shows incomplete implementation (truncated source, missing error handling). The resource definitions in mcp_data_gen.py show similar issues. Parameter descriptions are minimal (10-20 chars), schemas lack validation constraints, and the server provides no guidance on error recovery. The incomplete source code (get_ function truncated) suggests this is a work-in-progress. Overall definition quality barely meets minimum standards.
Creates a new product in the database.
Creates a new user in the database.
Deletes a product from the database by name.
Missing parameter descriptions on critical fields. 'password_hash' has no guidance on format (plaintext vs hashed); 'category_id' lacks explanation of valid ranges or how to discover valid IDs. Parameters named 'name' appear in both create_products and delete_products but lack disambiguation on case-sensitivity, uniqueness constraints, or handling of duplicates.
Delete tool has no confirmation or dry-run mechanism. delete_products is marked DESTRUCTIVE but provides no safety gates, no undo tool, and no guidance on error recovery. An agent could accidentally delete all products by typo.
No output schemas documented. The tools have no description of what they return on success or failure. For create_* tools, agents cannot know if they receive a new product_id or user_id, preventing chaining to downstream operations.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 44 | - | v1 |
password_hash parameter exposed directly in create_users. This violates secret-injection pattern: credentials should never appear as tool parameters. Passwords in agent traces leak into logs and prompt history.
No enum constraints on category_id parameter. create_products accepts any integer for category_id, but the database schema limits valid values to existing categories. LLMs will hallucinate invalid category IDs, causing failures with no guidance on recovery.
Tool descriptions are generic and lack WHEN-to-use guidance. 'Creates a new product in the database' could apply to any create_* tool. Missing: When should the LLM call this vs another tool? What are the prerequisites? What happens on duplicate product names?
No idempotency guidance. If an agent retries create_products with the same product name, the tool may create a duplicate or fail with 'unique constraint violation'. The description should clarify: is this idempotent? What happens on retry?
No error recovery guidance. Tool descriptions make no mention of what could go wrong or what the LLM should do on failure. Missing: Will MySQL constraint violations be caught? Will the LLM be told why a product creation failed?
Incomplete source code. The mcp_data_gen.py file shows a truncated get_ function definition. This suggests the server is incomplete or poorly tested. Cannot fully assess error handling or output schemas.
Resource definitions lack proper pagination and error handling. get_products returns a hardcoded LIMIT 3 and catches exceptions with a generic 'failed to fetch products' message. Agents cannot know if the call succeeded or failed, or how to retry.