Orca AI MCP Server for the HUNT platform API. This is a Model Context Protocol (MCP) server that provides integration with Orca AI's API. It supports dynamic configuration detection and provides tools for security analysis and HUNT searches.
The Orca AI MCP server has 2 tools with clear naming and typed schemas, but significant gaps in parameter descriptions, output documentation, and error handling. Tool names follow verb_noun convention (detect_*, get_*), which is good. However, parameter descriptions are minimal or missing, output schemas are not documented, and there is no structured error handling or guidance for LLMs. The tool definitions are visible in source code (OrcaAIMCPProxy.ts), so no inferential penalty applies.
Detect current Orca AI configuration and context
Search across Orca AI HUNT datasets with the provided query and return matching results
Missing output schema documentation. Neither tool documents what fields are returned or their types. LLMs cannot plan downstream calls or extract structured data without knowing the response shape.
Insufficient parameter descriptions. 'query' parameter in get_hunt_results only says 'Required non-empty search query' (33 chars). No guidance on format, length limits, search syntax, or example usage. Parameter descriptions should be 50-150 chars with actionable constraints.
Tool description for detect_orca_context is generic (43 chars: 'Detect current Orca AI configuration and context'). Does not explain WHEN to call it, WHAT it returns, or HOW to use returned values. Should be 100-200 chars with context and use case.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2025-06-18+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
No error handling or recovery guidance. No tool documents what errors can occur, how to interpret them, or what the LLM should do next (retry, ask user, fail). Error responses from source code are not visible.
nextToken parameter in get_hunt_results lacks description. No guidance on format, when to use it, or what happens when it is invalid. Pagination tokens require explicit documentation.
No pagination guidance in get_hunt_results description. Tool accepts 'nextToken' but description does not mention result limits, pagination behavior, or how many results to expect. LLM cannot determine if results are complete or partial.
No documentation of what fields detect_orca_context returns. Does it return API URL, token validity, feature flags, or all three? LLM cannot determine what to extract or how to use the response.