Robot Framework MCP Server - Natural Language Test Automation Bridge
rf-mcp provides 16 well-intentioned tools with mostly present descriptions and schemas, but exhibits significant gaps in consistency, parameter documentation, and output schema clarity. Tools follow verb_noun naming conventions (manage_session, execute_step, get_session_state), which is good. However, parameter descriptions are inconsistent, some parameters lack descriptions entirely, and many schemas are incomplete or missing type definitions for complex nested objects. Error handling guidance is absent across all tools. The tool set attempts to cover session management, keyword discovery, test execution, and web automation intents, but composition issues exist (e.g., intent_action combines multiple concerns into one tool with 11 parameters of varying necessity). Output schemas are not documented in the provided source, making it impossible to verify whether responses include necessary chaining IDs or are properly shaped for agent downstream operations. The server uses fastmcp (HTTP transport, current), which is positive, but tool annotation hints (readOnlyHint, destructiveHint, idempotentHint) are absent despite many tools being clearly destructive (execute_step, manage_session with delete action) or read-only. Conservative scoring reflects lack of visible schema definitions and incomplete parameter documentation across 12 of 16 tools.
Analyze a test scenario and return relevant keywords, libraries, and recommendations
Build a complete Robot Framework test suite from a scenario or specifications
Check if Robot Framework libraries are installed and available in the current environment
Execute a sequence of Robot Framework keywords in a structured flow
Execute a single Robot Framework keyword with arguments in a session
Search for Robot Framework keywords using semantic, pattern, or catalog strategies with optional library filtering
Get detailed information about a specific Robot Framework keyword including documentation, arguments, and tags
intent_action tool combines 11 parameters with overlapping concerns (click, fill, select, extract via a single 'intent' enum), violating single-responsibility principle. Parameters like 'value', 'match', 'mode', 'attribute_name' are conditionally required based on intent, but no parameter dependency documentation or conditional schema exists.
Output schemas are not documented in source. For 16 tools, no visible response schema definitions exist in the provided code samples. Cannot verify whether responses include necessary chaining IDs (e.g., session_id after execute_step for downstream calls), follow pagination patterns, or include proper error metadata.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 66 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 31 | - | v1 |
Get guidance on locator strategies and examples for Browser or SeleniumLibrary
Retrieve current session state including variables, loaded libraries, and execution history
Execute a high-level intent (click, fill, select, extract) on a web element, translating to library-specific keywords
Attach or detach external resources (files, libraries, services) to a session
Load, unload, or list Robot Framework library plugins
Create, retrieve, or delete a Robot Framework execution session
Get library recommendations for a test scenario with optional filtering by mode
Execute a Robot Framework test suite and return results and logs
Set the search order for Robot Framework keyword resolution
Destructive tools lack actionable error handling and confirmation/dry-run mechanisms. manage_session(action='delete'), execute_step, execute_flow, build_test_suite, run_test_suite, and manage_library_plugins(action='unload') can modify or destroy state but include no guidance on what to do if the operation fails, how to retry safely, or whether confirmation is required before execution.
Missing tool annotations. fastmcp supports readOnlyHint, destructiveHint, and idempotentHint, but none are applied. Tools like get_session_state, find_keywords, and check_library_availability should be marked read-only. Tools like execute_step, manage_session(delete), and run_test_suite should be marked destructive to help agents reason about safety and side effects.
Parameter descriptions lack clarity and constraints. Many parameters use single short phrases without specifying format, valid ranges, or dependencies. E.g., 'strategy' param in find_keywords lists enum values 'semantic, pattern, catalog' in description instead of using JSON Schema enum; 'assign_to' in execute_step lacks guidance on variable naming rules; 'options' in intent_action is described as 'Additional intent-specific options' without documenting what options are available.
Ambiguous parameter naming creates potential for LLM confusion. 'action' parameter in manage_session and manage_library_plugins is overloaded, different valid values for each tool. Parameter 'options' in intent_action is too generic. Response field naming conventions are not visible, risking mismatches between tool output and downstream tool inputs (e.g., does get_keyword_info return 'library_name' or 'library'?).
No pagination or result limiting documented for discovery tools. find_keywords, recommend_libraries, and analyze_scenario could return unbounded results. No limit, offset/page, or cursor parameters visible. Without pagination, large result sets will exhaust context windows and degrade agent reasoning.
Composition flaw: manage_attach tool mixes file attachment, library loading, and external service binding into a single tool with vague 'resource_type' and 'resource_path' parameters. Unclear how paths are resolved, what resource_types are valid, or what attachment does to the session state. Should be split into more specific tools (attach_file, load_library, connect_service).