MCP server providing access to multiple AI models with intelligent context management for large codebases.
Single tool 'search_mcp_debug_logs' has a problematic definition. While the tool name follows verb_noun pattern correctly, the description is excessively long (3000+ characters) with extensive embedded examples and syntax guide that should be external reference material. The input parameter 'query' has a type definition (string) and non-empty description, but the description itself is overly verbose (800+ characters) and includes example values, which LLMs tend to reuse literally. Output schema is not documented, the tool's return type/structure is not specified anywhere in the visible code. Error handling is absent; no guidance on recovery for malformed queries or service failures. The tool accepts raw, unvalidated user input (LogsQL query strings) with no input sanitization, which is a significant security concern for an internal debugging tool. The 'READ_ONLY' risk annotation is noted but tool annotations are not formally present in the schema.
Run a raw LogsQL query against VictoriaLogs debug logs (developer mode only). LogsQL pocket guide ─────────────────── QUERY CORE – one-liners _time:5m error # AND implicit, put _time first _time:5m error OR warning # use OR, NOT/-, and () for precedence {app="api"} error # label/stream filter status:error # field selector (default _msg) FILTER PATTERNS word : error # matches "error" anywhere phrase : "disk full" # exact phrase match prefix : erro* # prefix matching substring : _msg~"fatal" # substring search exact/multi : status:=500 # exact match : status:=(500,503) # multiple values range/cmp : latency_ms:>500 # comparison operators regex : url:~"/api/.+" # regular expression empty/any : user:_ # empty field : user:* # any value TOP PIPES (|) sort by (_time desc) # sort results limit N / head N # limit output fields f1,f2 # select fields stats count() by (endpoint) # aggregations where latency_ms > 1000 # filter after initial query top 10 endpoint # top values uniq by (user) # unique values extract "re" as x # regex extraction sample N # random sampling STATS FUNCTIONS count(), sum(x), avg(x), min/max(x), quantile(0.95)(x), histogram(x,bucket), rate(x), count_uniq(x), values(x) SPEED HINTS - Always start with _time:XXX to narrow time range - Use {label=value} filters early in query - Sort/regex only after initial filters - Use sample N for large result sets Examples ──────── 1. Last 20 errors _time:30m error | sort by (_time desc) | head 20 2. Top endpoints by slow (>1s) calls _time:15m latency_ms:>1000 | stats by (endpoint) count() slow | sort by (slow desc) | head 5 3. Per-minute error rate _time:1h error | stats by (bucket=_time(1m)) count() errors 4. Search specific app and severity _time:5m {app="mcp-the-force"} severity:error 5. Find specific text pattern _time:2h "CallToolRequest" {project="/Users/myproject"}
Description bloat: 3000+ characters with embedded LogsQL syntax guide, examples, and pocket guide. Should be 50-200 chars with external reference links.
Parameter description contains example values ('_time:1h', '_time:5m error OR critical') that LLMs will reuse literally in production calls instead of adapting to context.
Output schema not documented. No specification of what fields the LogsQL response contains, data types, pagination structure, or size limits. LLMs cannot plan downstream operations.
No error handling or recovery guidance. Tool accepts raw query strings with no validation. Malformed queries, timeout, or service errors return no actionable next steps for the agent.
Inferred effective spec: 2026-07-28+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 46 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 28 | - | v1 |
No input validation. Raw LogsQL queries are passed directly to VictoriaLogs without sanitization. Although marked 'developer mode only', this is a SQL-injection-like vector if the query string contains untrusted input.
No result pagination or size limits documented. LogsQL can return thousands of log entries. Without pagination parameters (limit, offset/cursor) or a documented result cap, agents risk context window exhaustion.
Tool description mentions 'developer mode only' but no mechanism is documented to enforce or verify this gate. No permission check or scope declaration visible.