The network-mcp server provides 42 tools across multiple network infrastructure domains (Arista, Batfish, Loki, PostgreSQL, Prometheus, TACACS). While tool NAMES are generally well-formed with action verbs (run_commands, get_bgp_summary, list_snapshots), the implementation exhibits critical gaps in schema depth, parameter documentation, and output structure specification. Examination of arista_tools.py, batfish_tools.py, and related modules reveals that most tools have descriptions present but lack comprehensive input/output schema documentation and parameter-level descriptions. The average tool description is adequate (60-120 chars observed), but parameter descriptions are inconsistent: some tools like run_commands document their parameters clearly (device_name, commands, encoding), while others (e.g., list_snapshots, get_latest_snapshot) have minimal or no parameter descriptions beyond the name. Output schemas are inferred from the source code (typically JSON-serialized results) but are NOT explicitly documented in tool registration. Error handling is present in code (try-catch blocks with JSON error returns) but lacks actionable recovery guidance for LLMs. No tool exhibits tool annotations (readOnlyHint, destructiveHint, idempotentHint), and there is no evidence of output schema declarations. This places the server in the C/D range: functional definitions with significant documentation gaps.
Get TACACS+ authentication failures.
Get bandwidth usage summary by interface, optionally filtered by node.
Simple reachability check - can src reach dst? Uses Batfish's reachability analysis on the Arista fabric. Returns ACCEPTED or DENIED with path details.
Search for commands matching a pattern in the TACACS+ audit trail.
Get all activity on a specific device.
Query failures and warnings from the ingest audit trail.
Get the BGP topology - which nodes peer with which.
CRITICAL: Output schemas NOT documented in tool definitions. Tools return JSON objects (inferred from code: json.dumps(result['result'])), but LLM has no declared schema for what fields to expect. This forces LLMs to reason about unstructured output and breaks downstream tool chaining.
HIGH: Tool annotations (readOnlyHint, destructiveHint, idempotentHint) are completely absent. load_snapshot is a WRITE operation (overwrite=True in code), but no tool declares this. LLMs cannot distinguish read-only queries from state-mutating operations, risking unintended side effects.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 56 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 45 | - | v1 |
Get non-established BGP sessions.
Analyse BGP session compatibility across all nodes.
Get BGP sessions, optionally filtered by node and status.
Get BGP summary from an Arista device.
Get interface properties. Optionally filter by node name.
Get interfaces for a node.
Get interface status and counters from an Arista device.
Get the latest snapshot for the configured network.
List discovered nodes and their configuration format.
Check which configs Batfish successfully parsed.
Get routing table for a node, optionally filtered by protocol.
Get routes for a node, optionally filtered by VRF, protocol, and network.
Get the IP routing table from an Arista device.
Get the full running config from an Arista device.
Get version and hardware info from an Arista device.
Check whether the Loki instance is reachable and ready.
Get interface counter metrics for a node, optionally filtered by interface.
Get interface error counters, optionally filtered by node.
List all configured Arista devices.
List all nodes that appear in Prometheus metrics.
List nodes in a snapshot.
List recent snapshots for the configured network.
Load or reload the network snapshot into Batfish.
Get the audit trail for a specific node across all snapshots.
Query pipeline run history from ingest service logs in Loki.
Execute a raw LogQL query against the TACACS+ audit trail in Loki.
Execute a raw LogQL query against Loki.
Get recent TACACS+ command accounting events, optionally filtered by device IP and username.
Query recent events from Loki filtered by lookback, category, and level.
Get recent TACACS+ login events, optionally filtered by device IP and username.
Run one or more show commands on an Arista device.
Get the full audit trail for a specific snapshot.
Get system boot time and last configuration change timestamps, optionally filtered by node.
Trace the path from source to destination through the network.
Get all activity for a specific user.
HIGH: Generic tool name 'query' used TWICE (Loki + TACACS). This creates ambiguity, LLM cannot distinguish which query tool to call. Pattern guidance: use verb_noun naming. Recommend: query_logql (Loki) and query_tacacs_audit (TACACS).
MEDIUM: Parameter descriptions incomplete or missing for multiple tools. Examples: get_parse_status, get_node_properties, get_latest_snapshot have NO parameters but no description explains WHAT data they return or WHEN to call them. list_devices also lacks detail on the structure of returned device objects.
MEDIUM: No pagination or result-limiting guidance in tool definitions. Tools like recent_events, recent_commands, node_history accept 'limit' parameters but descriptions do NOT state maximum allowed values or default behavior. Tools returning large datasets (e.g., get_running_config) lack truncation warnings.
MEDIUM: Error handling lacks actionable recovery guidance. Code shows try-catch blocks returning JSON errors (e.g., 'Connection failed to {device.host}'), but descriptions do NOT tell LLMs when to retry, what to try next, or which tools to call if lookup fails. Example: if run_commands fails due to device not found, description should guide: 'Call list_devices() first to verify device name.'