An MCP server providing secure OAuth authentication and data retrieval for GitHub and GitLab, with encrypted token storage in MongoDB.
This MCP server has severe definition quality issues. While tools are registered with basic schemas and descriptions, the implementation suffers from critical problems: (1) duplicate tool names across GitHub and GitLab (get_authorization_url, exchange_code_for_token, get_user_details appear twice with identical names), which violates the single-responsibility principle and will cause LLM confusion; (2) parameter descriptions are minimal and lack actionable context; (3) output schemas are completely undocumented, tools return plain strings rather than structured objects, making chaining impossible; (4) no error recovery guidance, errors are raw strings like 'Failed to fetch repositories' with no actionable next steps; (5) critical security issue: access tokens are passed through authentication flows but token management lacks comprehensive documentation; (6) parameter validation is absent, no constraints, enums, or format specifications; (7) tool descriptions are superficial (12-52 characters), well below the production baseline of 194 chars. The clone_repository and clone_project tools expose serious security risks by storing tokens in git URLs within local filesystem paths. Overall, this reads as a proof-of-concept rather than production-grade tooling.
Clone a repository of the authenticated user directly.
Clone a GitHub repository by its name for the authenticated user.
Exchange authorization code for access token and store it securely in MongoDB.
Exchange authorization code for access token and store it securely in MongoDB.
Generate GitLab authorization URL.
Generate GitHub authorization URL.
Fetch GitLab user details.
CRITICAL: Duplicate tool names across GitHub and GitLab. Tools named 'get_authorization_url', 'exchange_code_for_token', and 'get_user_details' appear twice with identical names but different implementations. LLMs cannot disambiguate and will select wrong tools, causing authentication failures and data mismatches.
CRITICAL: No output schemas documented. All tools return plain strings (e.g., 'Username: ..., Name: ...') instead of structured JSON objects. This prevents LLM tool chaining, downstream tools cannot parse results or extract needed IDs. Violates pattern:response-shaper.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 36 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 32 | - | v1 |
Fetch GitHub user details.
Fetch the projects of the authenticated user, including private repositories.
Fetch the repositories of the authenticated user.
HIGH: Parameter descriptions are missing or trivial (e.g., 'GitHub username' for get_user_details). No format constraints, no valid value ranges, no examples of acceptable input. Production baseline is 72 chars per parameter; most params here are <30 chars.
HIGH: Error responses provide no recovery guidance. Errors like 'Failed to fetch repositories' and 'Access token is invalid or expired. Please reauthorize.' are raw strings with no actionable next step for the LLM. Missing error classification (retryable vs. user-fixable vs. fatal). Violates pattern:recovery-guide.
HIGH: Security risk in clone_repository and clone_project. Access tokens embedded in git clone URLs and stored in local filesystem paths (./{repo_name}). Tokens logged in git history and command output. Violates pattern:secret-injection.
MEDIUM: Tool descriptions are superficial (12-52 chars). Production baseline is 194 chars (p10=34, p90=392). Current descriptions lack WHEN to use the tool, prerequisites, or disambiguation from similar tools. 'Generate GitHub authorization URL' tells LLM nothing about when to call it vs. exchange_code_for_token.
MEDIUM: No input validation or constraint documentation. Parameters accept free-form strings with no validation. For example, 'code' in exchange_code_for_token has no format or length constraint; LLM could pass invalid or malicious strings. Missing enums, regex patterns, and min/max bounds.
MEDIUM: No pagination support. get_user_repositories and get_user_projects return unbounded lists as newline-separated strings. No limit parameter, no offset/page, no total count. Large result sets will blow context window. Violates pattern:paginated-result.
MEDIUM: Duplicate tools named get_authorization_url and exchange_code_for_token for GitHub and GitLab create namespace collision. LLM cannot call 'the GitLab version', both have identical names. MCP protocol does not support overloading. Must rename (e.g., get_github_authorization_url, get_gitlab_authorization_url).