A Model Context Protocol server for comprehensive FoFa API integration with advanced cybersecurity features
The FoFa MCP server provides two tools with explicitly defined schemas and basic descriptions. However, significant gaps in parameter descriptions, output schema documentation, and error handling guidance reduce overall quality. The server is functional but falls short of production-grade standards. Naming follows verb conventions (search_, get_), which is positive. Input schemas are present and properly typed, but descriptions lack depth and output schemas are not documented. Parameter descriptions are minimal or absent in key areas.
Get user information from FoFa
Search FoFa's database for devices and services
Output schemas not documented for any tool. LLMs cannot determine what fields are returned, forcing them to infer structure or guess at downstream tool chain requirements.
Result pagination limit (hardcoded to 5 items via sampleResponse) is not declared in tool description. Users/agents cannot know results are truncated. Pattern:paginated-result requires explicit limit declarations.
Numeric parameters (page, size) lack bounds documentation. No minimum/maximum specified; no guidance on valid ranges. Agents could pass absurd values (page=999999, size=1000000) without validation hints.
get_user_info description is only 34 characters, below adequacy threshold. Lacks any detail on output fields, context, or purpose. Pattern:tool-description requires 10-1024 chars; this is technically in range but too terse to guide LLM selection.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 48 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
Error handling in implementation (McpError with ErrorCode.InternalError) provides raw API error messages but no recovery guidance. Pattern:recovery-guide requires actionable next steps (e.g., 'Invalid query format; try simplifying or check FoFa documentation').
Resource endpoints declared (fofa://search/example) but not integrated with tool invocation. Resources and tools operate independently, creating duplication and confusion about which path agents should use.