Static source inference · medium confidence · detected: Logging
Deprecated protocol patterns detected
Summary
This is a composite MCP host aggregating multiple servers (mattermost, ollama, simple-mcp-server, and internal agent tools). Critical assessment: (1) STDIO-only transport means the host cannot be remotely accessed or used by hosted MCP clients, architectural limitation capping overall quality. (2) Tool descriptions are generic and lack actionable context for LLM tool selection. (3) Parameter descriptions are minimal or absent in many tools. (4) No visible error handling guidance, recovery paths, or data type validation. (5) Output schemas are not documented. (6) Some tools like 'echo' and 'reverse' are trivial utilities with no domain value. (7) The 'calculator' tool uses unsafe eval() despite the comment claiming 'safe', security risk. (8) No pagination support on tools that return lists (e.g., list_teams, list_channels, get_posts). (9) No confirmation/dry-run patterns for destructive operations (create_post is the only write tool). (10) Field naming consistency issues across tool outputs (no way to verify from source). The server reads as a proof-of-concept or demo rather than production-ready.
Tools (14)
calculatorread onlysource verified50/100
Calculate the result of a mathematical expression.
No output schemas documented for any tool. LLMs cannot know what fields to expect, forcing them to guess or fail when chaining results into downstream tool parameters.
Trivial utility tools ('echo', 'reverse') offer no domain value and waste reasoning cycles for LLMs evaluating tool options.
echoreverse
Recommendations
Migrate from STDIO to HTTP+SSE or Streamable HTTP transport to enable remote client access and compliance with current MCP spec (2026-07-28).
Replace calculator's eval() with a safe expression parser (e.g., ast.literal_eval, sympy, or a constrained math library). Document allowed operations in the description.
Remove trivial tools (echo, reverse) that do not serve the agent's domain. Focus on Mattermost and Ollama integration.
Document output schemas for every tool. Example format: 'Returns {post_id: string, created_at: ISO8601, author_id: string, message: string, channel_id: string}'.Format: 'Returns {post_id: string, created_at: ISO8601, author_id: string, message: string, channel_id: string}'.
Add pagination to list tools: implement offset/limit or cursor-based pagination. Cap results at 50 items by default. Example: 'Retrieve up to 50 teams at a time. Use offset parameter for pagination.'
Add readOnlyHint and destructiveHint annotations to tool metadata for current MCP spec compliance. Mark create_post with destructiveHint and idempotentHint:false.
Enhance parameter descriptions with format guidance. Example: 'team_id (UUID format: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx)' or 'location (e.g., San Francisco, CA or 40.7128,-74.0060 for coordinates)'.
Add tool descriptions following the pattern: 'What it does. When to use it. Prerequisite tools or data needed. Expected output format.' Example for list_teams: 'List all Mattermost teams the authenticated user is a member of. Call this first to discover available teams before listing channels. Returns team_id, name, and description for each team.'
Spec posture evidence
Inferred effective spec: <=2025-11-25.
Relies on Logging (deprecated) - log to stderr or use OpenTelemetry
Score history
Overall score trend
↑ 21 points across a rubric change (v1 → v2)
47/100
Scored
Grade
Overall
Spec posture
Rubric
2026-09-22
F
47
<=2025-11-25
v2
2026-03-09
F
26
-
v1
Get posts from a channel
list_channelsread onlyauth50/100
List all channels in a team
list_modelsread onlysource verified58/100
List all available models from Ollama
list_teamsread onlyauth50/100
List all teams the user is a member of
reverseread onlysource verified48/100
Reverse a message
searchread onlysource verified57/100
Mock implementation of Search for information based on a query.
List tools (list_teams, list_channels, get_posts) lack pagination controls (offset, cursor, next_token) and cap (explicit limit in description). Large result sets can exhaust LLM context windows.
Only one write tool (create_post) exists with no idempotency hint, no dry-run/confirmation step, and no destructive operation warning in description. Agents cannot safely retry failed calls.
Parameter descriptions are often absent or generic (e.g., 'Team ID', 'Channel ID', 'Location'). LLMs do not know what format to use (UUID, slug, email, integer, etc.).
Tool descriptions lack context for LLM selection. 'Mock implementation of Search...' and 'Get the weather...' do not explain WHEN to use this tool vs similar ones or what prerequisites exist.
Tool chaining references undocumented. If create_post returns a post_id, subsequent tools should accept it, but response structure is not specified. Agents cannot reliably pass IDs between tools.
create_postget_postslist_channels
For generate_text and chat_completion, document parameter interdependencies. Example: 'system_prompt is optional; if omitted, uses Ollama default. model parameter accepts names from list_models() output.'
Add idempotent operation support: create_post should include an idempotency_key parameter so repeated calls with the same key return the same post_id without duplication.
Implement dry-run confirmation for create_post: add a 'dry_run' parameter (boolean, default false) so agents can preview before actual creation.
Add error recovery guidance in descriptions. Example: 'If channel_id is invalid, use list_channels(team_id) to discover available channels.' Add explicit enum or regex patterns for known-value parameters.
Return related IDs in responses to enable downstream chaining. Example: get_posts() should return {posts: [{post_id, message, author_id, channel_id, created_at}], channel_id, team_id, total_count}.
Validate all parameters and return actionable error messages. Example instead of bare 404: 'Channel "xyz" not found. Available channels: general, random, dev-team. Try one of these or use list_channels() to search.'
Add per-tool logging with LLM-friendly context. Example: log tool calls with {tool_name, parameters, result_summary, timestamp, caller_user_id} for audit trails.