Customer analytics MCP server with multi-system workflows: database queries, health scoring, and external data integration
Server demonstrates solid patterns in naming (verb-noun convention), parameter constraints (enums, defaults, min/max), and permission-gated access. Both tools follow action-verb naming and have detailed descriptions (130-220 chars). Input schemas are present with typed parameters and descriptions. However, output schemas lack formalization in schema objects, descriptions could be more LLM-optimized (10-50 words vs current 1-3 word), and no explicit tool annotations (readOnlyHint, idempotentHint) despite clear read-only semantics. Error handling returns structured metadata but lacks actionable recovery guidance (no 'try X next' hints). Security controls are present (role-based filtering, permission checks) but inconsistently documented across tools.
Analyze customer health by combining order data with external signals (NPS, support). Returns risk scores, segments, and actionable insights. Demonstrates multi-system workflow patterns.
Execute a read-only SQL query (SELECT only) against the demo DB. Requires appropriate permissions.
Output schemas not formally declared in tool definitions. Both tools have code-level response structures (rows/rowCount/metadata for run_sql; risk/segment/insights inferred for compute_account_health) but these are not visible in the tool registration schema objects, violating pattern:tool and pattern:response-shaper. LLM cannot verify expected output shape.
Descriptions lack LLM-optimized phrasing. Both are under-specified on WHEN to call and WHAT to do with results. E.g., compute_account_health description omits: which customer segment should I query? What do the risk scores mean (0-100)? What are 'actionable insights', remediation steps?. Should include dependency hints ('Call search_customers first to get segment membership').
No explicit tool annotations despite clear semantics. Both tools are read-only and idempotent, but schema lacks readOnlyHint and idempotentHint annotations. Per MCP 2026-07-28 spec, tool annotations guide LLM behavior (retry policy, caching, permission decisions).
Inferred effective spec: 2025-06-18+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 71 | 2025-06-18+ | v2 |
| 2026-03-09 | F | 44 | - | v1 |
Error responses lack actionable recovery guidance. When SQL is invalid or permissions denied, responses return bare error strings ('Only SELECT queries are allowed') instead of guided next steps (e.g., 'Only SELECT queries allowed. Try: SELECT * FROM users LIMIT 10'). Per pattern:recovery-guide, errors should tell LLM what to do.
Parameter 'sql' accepts free-form strings with no validation hints in description. While tool includes guardrails (parseSQL checks), description should state format explicitly: 'A SELECT-only SQL query. Cannot contain INSERT, UPDATE, DELETE, DROP. Add LIMIT to avoid large result sets.' LLM has no way to self-validate before calling.
Compute_account_health's output shape undefined. Description mentions 'risk scores, segments, actionable insights' but code does not show structured response schema. If agent receives {risk: 0.8, segment: 'inactive', reasons: [...]} it cannot validate field types or know which fields are always present vs conditional.