A Cloudflare Workers MCP server with OAuth 2.0 authentication and Supabase integration
This server has three tools but suffers from critical quality gaps. Tool naming partially follows verb_noun convention, but descriptions are generic and lack sufficient detail for LLM selection. Critically, tool input schemas appear incomplete or inferred from parameter lists rather than formally defined JSON Schema. The configure_supabase_instance tool accepts sensitive credentials as parameters (violating secret-injection pattern), and there is no evidence of structured output schemas, error categorization, or recovery guidance. The add() utility tool is trivial and does not justify inclusion. The codebase shows OAuth infrastructure and Supabase integration setup, but the actual tool implementation details in MySupabaseMcpAgent.ts are truncated in the source provided, making full schema validation impossible.
Adds two numbers.
Configures the Supabase instance details (URL, anon key, service key) for the current session.
Lists all accessible tables in the configured Supabase database.
Credentials exposed as tool parameters (supabaseUrl, supabaseAnonKey, supabaseServiceKey in configure_supabase_instance)
Generic, short descriptions lack LLM guidance for tool selection
No error categorization or recovery guidance
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 45 | 2025-06-18+ | v2 |
| 2026-03-09 | F | 38 | - | v1 |
Parameter descriptions are minimal or missing context