The auditPackage tool has a single responsibility but suffers from critical definition quality issues. The tool name 'auditPackage' uses camelCase instead of the verb_noun snake_case convention (should be 'audit_package'), which hampers LLM parsing. The description is in Chinese, limiting accessibility to English-speaking LLM contexts. Input parameters lack proper JSON Schema typing, they are defined as Zod strings but the schema object shown lacks explicit 'type' and 'required' fields in JSON Schema format. The parameters have Chinese descriptions which, while descriptive, are language-locked. No output schema is documented, the tool returns a text string but callers have no structured contract for what fields or structure to expect. Error handling is absent, the tool silently succeeds or throws unhandled exceptions with no recovery guidance. The tool modifies filesystem state (writes to savePath) but the description does not explicitly warn of this destructive behavior, violating the command-tool pattern. Overall, this is a minimal, functional definition that lacks production-grade polish.
审计前端工程的所有直接和间接依赖,得到安全审计结果。支持本地工程的审计,也支持远程仓库的审计。审计结果为标准格式的markdown字符串,不用修改,直接用于展示即可。
Tool name uses camelCase (auditPackage) instead of verb_noun snake_case convention (audit_package). LLMs rely on name parsing to infer intent; non-standard naming increases misclassification risk.
Input parameters lack proper JSON Schema type declarations. Zod schema is used in code but the schema object does not explicitly show 'type': 'string' fields, nor are parameters marked 'required'. Schema viewers cannot validate input without explicit typing.
No output schema documented. The tool returns {content: [{type: 'text', text: string}]} but callers have no formal contract for the response structure. LLMs cannot plan downstream steps without knowing what fields are available.
All descriptions (tool, parameters) are in Chinese, limiting accessibility to English-speaking LLM contexts and reducing cross-language tooling adoption. MCP best practice is to use English for interoperability.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 29 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 24 | - | v1 |
Tool performs destructive filesystem operations (writes audit.md to savePath) but the description does not explicitly state that state is modified. Missing command-tool pattern declaration.
No error handling or recovery guidance. If auditPackage fails (network error downloading repo, invalid path, permission denied), the exception is unhandled. Tool should return actionable error messages telling the LLM what to do next.
Parameter descriptions lack constraints and examples. 'savePath' should specify 'absolute path, must be writable, .md extension recommended' and similar detail. Currently vague.
Tool accepts projectRoot as either local path or remote URL but does not document format constraints or valid examples. Should state: 'Local: absolute path (e.g., /home/user/project). Remote: https://github.com/owner/repo.'