The MCP quick start repo is to help make a start at MCP development, with an example tool already created.
Single tool with incomplete definition quality. The tool 'summarise_pbip' has a basic description and input schema, but lacks critical elements: no output schema documentation, minimal parameter description, no error handling guidance, and no enum/constraint definitions. The tool performs a file-system read operation but provides no validation, no pagination support for potentially large results, and no recovery guidance for edge cases (missing project_path, permission errors, malformed JSON files). Tool name is acceptable but description is generic and under-optimized for LLM invocation.
Reads the key components of a PBIP project and summarizes its contents.
No output schema documented. The tool returns a dict but LLMs cannot infer structure. No documentation of what fields are present, their types, or when they might be absent (e.g., if .PBIP file doesn't exist).
Input parameter 'project_path' has minimal description. No guidance on format (absolute vs relative path), what happens if path doesn't exist, whether it should be a file or directory, or error recovery strategy.
No error handling or recovery guidance. Tool will crash or return partial results silently if: project_path is invalid, JSON files are malformed, permissions are denied, or required folders are missing. No error messages guide the LLM on retry or alternative actions.
Potential path traversal vulnerability. Tool accepts arbitrary 'project_path' parameter with no validation. An LLM could be tricked into passing '../../../etc/passwd' or similar malicious paths, exposing sensitive files.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 37 | - | v1 |
Tool returns entire file contents (JSON and .tmdl files) with no pagination or size limits. A large PBIP project could return megabytes of data, exhausting context window and increasing hallucination risk. No limit stated in description.
Hardcoded folder names ('HRB-Reporting-Bugs.Report', 'HRB-Reporting-Bugs.SemanticModel') are not documented in parameter description. LLM cannot know whether these are always present or project-specific, or what to do if they're absent.