A Rust-based MCP server providing tools for Aliyun CLI, Log Service, MySQL, Redis, Elasticsearch, Nacos configuration management, and time utilities
This server exposes 25 tools with significant definition quality gaps. While tool names follow verb_noun conventions (RunAliyunCliCommand, ExecuteMySQLQuery, ESSearch), descriptions vary widely in quality and usefulness. Many tools have adequate parameter descriptions, but critical patterns are missing: no tool annotations (readOnlyHint/destructiveHint/idempotentHint), no documented output schemas, no error handling guidance, and no pagination support for list operations. Input schemas are present and typed for most tools, but descriptions are often generic or example-heavy (violating the no-example-values rule). Security concerns are significant: RunAliyunCliCommand and ExecuteRedisCommand accept arbitrary CLI commands as strings, inviting command injection if not validated. The server lacks idempotency guarantees, confirmation patterns for destructive ops (delete, write), and comprehensive error recovery guidance.
Retrieve aliases for a specific Elasticsearch index
Retrieve the health status of an Elasticsearch cluster
Retrieve detailed information about a specific Elasticsearch index
Retrieve the mapping/schema for a specific Elasticsearch index
Retrieve the version of an Elasticsearch cluster
Check if a specific Elasticsearch index exists in the given configuration. Takes the configuration name and index name as parameters, and returns a boolean result. Useful for automated tools (such as cursor) to validate index presence before performing further actions.
Command injection vulnerability: RunAliyunCliCommand and ExecuteRedisCommand accept arbitrary CLI command strings without input validation. LLM-generated commands could include shell metacharacters, command chaining (;, &&, |), or malicious subcommands.
No output schemas documented for any tool. LLMs cannot infer what fields are returned, their types, or how to chain tools together. This breaks composition patterns and forces LLMs to guess field names.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 57 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 50 | - | v1 |
List all available Elasticsearch configurations, including name, URL, version, environment, and description for each configuration. This allows automated tools (such as cursor) to enumerate and select the appropriate Elasticsearch cluster for further operations.
Execute a search query against a specific Elasticsearch index
Execute a MySQL SELECT query and return results. Only SELECT queries are allowed for security reasons.
Execute a Redis command and return results. Write operations are not allowed in production environment.
Get all configuration information
Get current server time in YYYY-MM-DD HH:MM:SS format, no parameters required
Retrieve the full configuration of all Elasticsearch indices as defined in the system, including index names, field mappings, and metadata. This is useful for automated tools (such as cursor) to discover available indices and their field structures for further queries or validation.
Given an Elasticsearch index name, return the detailed field configuration (mappings, types, and metadata) for that specific index as defined in the system configuration. This enables automated tools (such as cursor) to programmatically inspect index schemas and validate field usage.
Get Nacos configuration information
Get Nacos configuration information for specified namespace and data_id
Get Nacos registered service instance information for specified namespace and service name
Get SLS (Simple Log Service) configuration information
List all available MySQL connections
List all available databases in a MySQL connection
List all tables in a specific database
List all available Redis connections
List all available databases in a Redis connection
Execute any aliyun CLI command and return results. Example: {"command":"sls GetLogs --ProjectName ack-test-cluster-log --LogstoreName user-center-api --from 1718000000 --to 1718003600"}
Execute aliyunlog CLI log subcommand and return results. If unsure about what to execute, first call the GetConfig MCP tool to get configuration information. If time is involved, first call GetCurrentTime to get the current time. Example: {"command":"log get_log_all --project=xxx --logstore=xxx --from_time=2024-06-01 --to_time=2024-06-02"}
No tool annotations (readOnlyHint, destructiveHint, idempotentHint) present. Cannot distinguish read-only tools from write operations. Agents cannot reason about safety of retry behavior or need for confirmation.
Missing error recovery guidance. Tools lack descriptions that categorize errors as retryable, user-fixable, or fatal. No examples of 'not found' recovery (e.g., 'Channel not found. Try ListMySQLConnections() first.') that enable agent self-correction.
Generic, short descriptions (under 50 chars) for many tools. GetConfig (29 chars), GetSLSConfig (40 chars), GetNacosConfig (28 chars), ListMySQLDatabases (40 chars), ListMySQLConnections (39 chars), ListRedisDatabases (43 chars), ListRedisConnections (37 chars) do not explain WHAT they return, WHEN to use them, or WHY they exist. Violates tool-description pattern.
No pagination support for list tools (ListMySQLDatabases, ListMySQLTables, ListMySQLConnections, ListRedisDatabases, ListRedisConnections). Large result sets can exhaust context windows. Tools should accept limit/offset and return total count or next_cursor.
No result limits documented or enforced. ESSearch, ExecuteMySQLQuery can return thousands of rows, blowing context window and degrading LLM reasoning. Should cap results (e.g., 20-50) and offer pagination.
Tool descriptions include example command strings (RunAliyunCliCommand, RunAliyunLogCliCommand). LLMs tend to reuse examples literally rather than adapt them. Should be removed and constraints specified via enums or pattern validation instead.
No idempotency guarantees documented. If an agent retries ExecuteMySQLQuery, ExecuteRedisCommand, or RunAliyunCliCommand on transient failure, could create duplicates or cause side effects. Missing idempotent-operation pattern.
No confirmation or dry-run pattern for destructive operations (RunAliyunCliCommand, ExecuteRedisCommand with write commands). Agents can delete data without user confirmation.