MCP server for creating and managing Grafana dashboards with ClickHouse data source
Single tool (create_time_series_dashboard) with a well-defined schema and comprehensive docstring, but significant gaps in production readiness. The tool has an explicit input schema with all parameter types defined and descriptions provided. The docstring is unusually detailed (794 chars), exceeding the typical range but providing concrete SQL contract guidance. However, error handling is minimal, output schema is not documented, and the implementation exposes security concerns around credentials. The tool name follows verb_noun convention correctly ('create_time_series_dashboard'). Parameter naming is mostly clear (title, raw_sql, description, panel_title, make_public), though 'raw_sql' could be more descriptive. The optional parameters have defaults, which is good practice. Overall, the tool definition quality is above average for a single-tool server, but falls short of production-grade due to undocumented output, weak error messages, and credential handling issues that impact the overall score.
Create a Grafana dashboard (ClickHouse data-source) with a single **Time-series** panel.
Output schema is not documented. The tool returns a JSON object but the structure and fields are not specified in the description or docstring. LLMs cannot plan downstream operations or extract the public_url field without seeing the schema.
Error handling provides no recovery guidance. When GRAFANA_API_TOKEN is missing or the API call fails, exceptions are raised with generic messages like 'GRAFANA_API_TOKEN environment variable is not set.' The LLM receives a raw error with no actionable next steps (e.g., 'Check your .env file' or 'Verify the token is valid').
Credentials are injected via environment variables (GRAFANA_API_TOKEN, GRAFANA_URL, GRAFANA_DATASOURCE_UID) at server startup, which is correct. However, there is no documented audit trail, logging of who called the tool, or permission gates. The tool creates a write operation (modifies Grafana state) without logging or access control.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 69 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 42 | - | v1 |
No input validation on raw_sql parameter. The docstring specifies a detailed SQL contract (e.g., must include $__timeFilter macro, no trailing semicolon, specific column naming), but the implementation does not validate the SQL before sending it to Grafana. A malformed query will fail silently at the API level with no helpful error message.
Error handling when make_dashboard_public fails is silently suppressed with a generic print() statement. If the public dashboard creation fails, the error is logged to stdout (not stderr) but the tool still returns success. An LLM cannot distinguish between partial failure (dashboard created, public URL failed) and full success.
The 'description' parameter is optional and defaults to None (empty string), but the docstring does not clarify whether an empty description is valid or encouraged. The panel description is set to an empty string if not provided (description if description else ''), which may be acceptable but is not explicit in the parameter description.