An Extensible MCP Server with support for Redis, MongoDB, and Memgraph database operations
This MCP server exposes 12 database tools (Memgraph, MongoDB, Redis) with HTTP transport. Tool definitions are present and descriptions are substantive (100-300 chars each), which is above baseline. However, there are significant gaps: (1) Parameter descriptions lack constraint details (enums, ranges, formats); (2) Output schemas are not documented anywhere in the code provided; (3) Error handling guidance is minimal, no recovery instructions or actionable error messages; (4) Some parameter semantics are ambiguous (e.g., 'from' and 'to' in memgraph_relationship_create accept match conditions as strings, but LLMs will struggle to formulate correct Cypher syntax without examples or validation); (5) No evidence of input validation or sanitization against injection attacks, which is critical given that tools accept raw query strings and JSON. The server follows a clear naming convention (verb_noun) and most tools are single-responsibility, which is good. But the lack of output schema documentation and weak error handling prevent this from reaching 70+.
Create graph node. USE: storing entities. RETURNS: created node. Maps to: CREATE Cypher statement
Execute read-only Cypher query. USE: search, retrieval, analysis. RETURNS: query results. Maps to: Cypher query execution
Execute Cypher query. USE: write operations, mutations. RETURNS: query results. Maps to: Cypher query execution
Create relationship between nodes. USE: linking entities. RETURNS: created relationship. Maps to: CREATE relationship Cypher
Delete documents from a MongoDB collection. Removes one or multiple documents matching a filter. WARNING: Delete operations are permanent. Maps to: MongoDB deleteOne() or deleteMany() operations
Find documents in collection. USE: retrieving, searching, filtering. Maps to: MongoDB find()
Output schemas undocumented for 11 of 12 tools. No formalized specification of what each tool returns (fields, types, pagination).
Parameter descriptions lack constraint details. Many parameters accept strings or JSON without specifying format, length limits, allowed values, or validation rules. Examples: memgraph_relationship_create 'from'/'to' accept arbitrary match conditions with no Cypher syntax guidance; mongodb_document_find 'query' is JSON-encoded with no schema validator.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 67 | <=2025-11-25 | v2 |
Insert one or more documents into a MongoDB collection. Supports single document or bulk insert operations. Maps to: MongoDB insertOne() or insertMany() operations
Update documents in a MongoDB collection. Uses MongoDB update operators to modify documents. Maps to: MongoDB updateOne() or updateMany() operations
Execute raw Redis command and return result. Supports any Redis command (GET, SET, KEYS, SCAN, HGET, LRANGE, etc.) Examples: - "GET mykey" - Get value of key - "KEYS ref:*" - Find all keys matching pattern - "TTL mykey" - Get time to live - "HGETALL myhash" - Get all hash fields - "LRANGE mylist 0 10" - Get list range - "SCAN 0 MATCH ref:* COUNT 100" - Scan keys with pattern WARNING: Destructive commands (DEL, FLUSHDB, etc.) will execute. Use with caution. Direct pass-through to Redis server.
Check if key exists and get TTL. RETURNS: exists (boolean), ttl (seconds or null if key doesn't exist) Maps to: Redis EXISTS + TTL commands
Redis GET command - retrieve full data from key. WARNING: This loads full data into LLM context. Use sparingly. Prefer redis_inspect for exploration. Use this to: - Final step before presenting to user - When you need complete dataset for analysis - After reducing dataset to small result set Maps directly to: Redis GET command
Get metadata + preview + TTL for key (composite operation). USE: Exploration before full load, check size/structure/expiration, verify key exists DO NOT USE: When you need full data (use redis_get instead) RETURNS: Metadata (type/size/count), preview (first 3 items), TTL (seconds) Maps to: Redis GET + TTL commands
No error recovery guidance. Tools do not document what errors can occur or how to recover. For example, memgraph_node_create does not explain what happens on duplicate node or constraint violation. MongoDB tools do not explain behavior when collection is not found or query is invalid.
No input validation or injection prevention visible in source. Tools accept raw Cypher queries, JSON filters, and Redis commands without sanitization. This is a critical security risk, especially for redis_command which allows arbitrary commands and mongodb_* tools which pass JSON-encoded queries without validation.
redis_command is a dangerous pass-through with no guardrails. It accepts arbitrary Redis commands (GET, SET, DEL, FLUSHDB) with no validation, allowlist, or error guidance. This violates single-responsibility principle and creates a security vector for runaway agents.
Destructive operations (mongodb_document_delete, memgraph_query_run with write capability) lack confirmation steps or dry-run options. No tool supports rollback or requires multi-step confirmation before executing irreversible changes.
JSON string parameters (mongodb_document_find, mongodb_document_insert, etc.) force LLMs to manually construct JSON, which is error-prone and lacks schema validation. Better approach: accept structured objects with explicit field schemas.
Inconsistent parameter naming conventions. MongoDB tools use '_limit' and '_multiple' as special inline keys rather than separate parameters. Redis tools use 'key', but Memgraph uses unnamed match conditions in strings. This forces LLMs to reason about different conventions for similar operations.