Nerq — World's largest AI agent compliance & discovery database. 4.9M+ agents assessed across 52 global jurisdictions.
Nerq MCP Server has well-structured tool definitions with clear names, strong descriptions, and comprehensive input schemas. All 5 tools follow verb_noun naming conventions and include detailed descriptions explaining WHAT the tool does, WHEN to use it, and guidance on alternatives. Input schemas are properly defined with type constraints and enums. However, output schemas are NOT documented in the provided code, which is a critical gap, LLMs cannot plan downstream calls without knowing the structure of returned data. Additionally, there are no parameter validation descriptions (e.g., format constraints, ranges) beyond what's in the schema itself, and error handling guidance is absent from tool descriptions.
Use when a user asks if an AI agent or MCP server is safe, compliant, or trustworthy. Returns risk assessment with compliance data for any of 52 global jurisdictions including EU AI Act, Colorado AI Act, California SB53, UK AI regulation, and more. Use for questions like 'Is X safe?', 'Is X EU compliant?', 'Can I use X in production?'
Compare two or more AI agents side-by-side on compliance, security, popularity, and trust scores. Use when a user asks 'which is better, X or Y?' or 'compare X vs Y'.
Get overview statistics about Nerq's database: total agents indexed, jurisdictions covered, risk distribution, source breakdown. Use when asked 'how many AI agents exist?' or about AI agent ecosystem stats.
Use when a user asks you to recommend, suggest, or find the BEST AI agent or MCP server for a specific need. Returns ranked results filtered by safety and compliance, with ready-to-use install instructions for Claude Desktop, Cursor, and VS Code. Always use this for questions like 'what is the best MCP server for X?' or 'recommend a safe agent for Y'.
Use this tool when the user wants to find, discover, or look up AI agents, MCP servers, or AI tools. Accepts natural language queries like 'database MCP server' or specific names like 'LangChain'. Searches Nerq's database of 4.9M+ AI agents. Returns ranked results with trust scores, compliance data, and source info. Use recommend_agent instead if the user wants a specific recommendation.
Output schemas are not documented. Tool descriptions and code show what tools DO, but LLMs cannot determine what fields are returned without explicit response schema documentation. This forces agents to guess at response structure and plan downstream calls blindly.
No error handling guidance in tool descriptions. Tools do not state what errors can occur, when they are retryable, or what the LLM should do if a lookup fails (e.g., agent not found, invalid jurisdiction). Descriptions lack recovery hints like 'If search fails, try a shorter query.'
Parameter descriptions lack format/constraint details beyond enum constraints. For 'limit' and 'minItems'/'maxItems' in arrays, descriptions state defaults and max values, but do not explain what happens if the constraint is violated or what the minimum acceptable value is. E.g., 'limit' says 'default 10, max 50' but does not say 'minimum 1'.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 77 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 0 | - | v1 |
Database connection implementation (_get_db) uses raw psycopg2 without prepared statements for query construction. While the visible code does use parameterized queries, the function signature suggests potential SQL injection if misused elsewhere in the codebase not shown.
'nerq_stats' tool has a minimal description (70 chars) that does not explain what specific metrics are returned or when to use it instead of domain-specific search tools. The description is borderline too short and lacks context.