An MCP server demonstrating enterprise system integration with employee database queries, bonus calculations, and server health monitoring capabilities
This server presents significant definition quality gaps. While tool names follow verb_noun convention (query_employee, calculate_bonus, analyze_server_health), the descriptions lack sufficient depth for LLM-driven tool selection. Critically, the query_employee tool exposes a DESTRUCTIVE operation (arbitrary SQL execution) without any safety guardrails, confirmation steps, or input validation guidance. Parameter descriptions are present but minimal (10-30 chars), leaving LLMs to infer intent. No output schemas are documented, forcing agents to guess at response structure. The server lacks error guidance and security controls expected in production tools.
Analyzes current server telemetry and returns a summary report.
Calculates the exact bonus amount based on salary and performance score (1-5).
Executes a SQL query on the 'employees' table. Columns: id, name, role, salary, performance.
query_employee accepts arbitrary SQL string with no input validation, sanitization, or SQL injection protection. This is a critical security vulnerability and a destructive operation without confirmation.
No output schemas documented for any tool. Agents cannot know what fields to expect in responses (e.g., does calculate_bonus return a float, a string, an object?). This forces agents to guess and wastes tokens parsing unstructured output.
Parameter descriptions are vague and too short (<40 chars). 'SQL query to execute on the employees table' gives no guidance on valid syntax, constraints, or error recovery. 'Employee salary amount' does not specify min/max range or precision.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 39 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 33 | - | v1 |
No error handling or recovery guidance. query_employee returns 'SQL Error: {str(e)}', raw exception text that gives agents no actionable next steps. Should categorize errors (syntax vs permissions vs timeout) and suggest recovery actions.
Tool annotations (readOnlyHint, destructiveHint, idempotentHint) are missing. The server declares query_employee as DESTRUCTIVE in metadata but does not enforce this in the tool schema. This mismatch could allow agents to treat it as safe.
Resources are defined (system://logs/latest, biz://policy/bonus) but not connected to tools that might use them. No guidance on when to call get_bonus_policy before calculate_bonus, or when to consult get_system_logs before analyze_server_health.