An MCP server that integrates Salesforce CRM with a conversational AI agent powered by Gemini and LangGraph. It acts as an integration hub connecting Salesforce and external services (knowledge base, inventory, marketing, ERP, CDP) through tool-based interactions.
This MCP server has significant definition quality issues. Of 10 tools, all have descriptions and basic input schemas, but most lack essential structural properties: no output schemas are documented, parameter descriptions are generic and inconsistent, error handling guidance is absent, and security-sensitive tools (commit_code_changes, write operations across multiple systems) lack confirmation patterns or permission gates. The tool definitions exist but are incomplete, descriptions average ~120 chars (below the 194-char baseline), and critical operational context is missing. The server simulates external system integrations (Salesforce, inventory, ERP, CDP, marketing platform) but provides no guardrails for irreversible operations. No tools implement idempotent patterns, no batch operations exist despite loops being obvious (e.g. syncing contacts), and chaining IDs are not consistently returned.
Commits a file to the Git repository with a specific commit message. This is a sensitive tool. Use only when explicitly told to commit a configuration change or code fix. Requires a detailed commit_message and the relative file_path to be committed. For safety, this tool only simulates the git commands.
Retrieves details for a specific case from Salesforce using its case number. Use this tool when a user asks for the status, priority, subject, or description of a specific case.
Logs a customer interaction or assigns a task in Salesforce. Requires a subject, the ID of the related record (like a Contact or Case ID), and a description. Optionally, you can assign it to another user by providing their Salesforce user ID in 'assignee_id'.
Searches the knowledge base for articles related to a given search term. Use this for general questions, how-to guides, or troubleshooting information.
Pushes a full, updated contact profile to the central Customer Data Platform (CDP). This tool should be used after a contact record is updated to ensure the unified customer view is current. Requires the Salesforce contact_id and a dictionary of the complete contact data.
No output schemas documented for any tool. LLMs cannot predict what fields to expect, forcing them to parse unstructured responses and breaking downstream tool chaining.
Destructive/irreversible tools (commit_code_changes, all update_* and upsert_* tools) lack confirmation patterns or dry-run support. Agents can permanently delete, overwrite, or commit code without guardrails. commit_code_changes description says 'simulates' but provides no actual confirmation mechanism.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 54 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 45 | - | v1 |
Updates a customer's record in the ERP system (e.g., SAP, NetSuite). Use this to change critical financial information like billing addresses or payment terms. Requires the ERP customer_id and a dictionary of the financial data to update.
Updates the inventory count for a product in the external inventory database. Use a positive number for quantity_change to add stock, and a negative number to remove stock.
Updates a subscriber's profile in the company's marketing automation platform (e.g., Marketo, HubSpot). Use this to sync changes to a customer's contact preferences, name, or email address. Requires the user's email and a dictionary of the data to update.
Updates a customer's contact record in Salesforce, or creates a new one if it doesn't exist. The operation is based on the customer's email address. Requires the customer's email and a dictionary of fields to update, e.g., {"Phone": "555-123-4567"}.
Creates a new lead record in Salesforce or updates an existing one based on the email address. Use this when a user asks to create or update a lead or prospect. Requires email, company, last_name, first_name, and phone.
No permission gates or access control checks documented. Tools operate across 4+ business-critical systems (Salesforce, ERP, CDP, Marketing, Inventory) without role-based access control. No audit trail pattern visible in code.
Parameter descriptions lack actionable constraints. E.g., 'fields_to_update' is described as 'Dictionary of fields to update for the contact record', no validation rules, no enum of allowed fields, no format guidance. 'new_data' and 'new_financial_data' are equally vague across multiple tools.
No error handling guidance. Functions return success/error dicts in external_integrations.py but no recovery instructions. E.g., 'Product SKU {product_sku} not found', agent is not told to try search_products or retry with a corrected SKU.
log_and_assign_task conflates two concerns (logging AND assigning). Should be split into log_customer_interaction and assign_task so agents can compose them independently. Parameter 'assignee_id' is optional but no guidance on what happens if omitted.
No idempotency guarantees. upsert_* tools claim to 'create or update', but source code shows only simulated state. No documented retry behavior, if an upsert times out mid-flight, rerunning it could duplicate records.
Tool chaining IDs missing. get_salesforce_case_details returns case details but no documented fields, agent cannot extract case ID to chain into log_and_assign_task without guessing field names.
No batch operations despite obvious loops. Agents syncing 10 contacts to CDP would call sync_contact_to_cdp 10 times sequentially, no batch_sync_contacts_to_cdp variant exists.
Credentials/secrets not visible in parameter lists (good) but code shows hard-coded integrations initialized in langgraph_agent.py. No documentation of how secrets are injected (environment variables not shown in actual tool registration).