MCP server for CommCare Connect API integration
This server exhibits significant quality gaps across naming, descriptions, schemas, and error handling. While tool names follow verb conventions (get_*, add), three of four tools expose sensitive configuration (API key, server endpoint) as parameters rather than using server-side injection. Descriptions vary widely in quality, some are adequate (get_global_stats at 98 chars) while others are trivial (get_api_key at 11 chars, below the 20-char minimum). Parameter schemas are present but inconsistent: get_global_stats has proper typed parameters with descriptions, while get_ccc_server and get_api_key have empty input objects. The add tool is out of scope (demonstration tool, not domain-relevant). Output schemas are not documented, callers must infer return types from tool names. Error handling is absent; no validation, no recovery guidance, no timeout handling for the requests.get() call. The server returns raw API responses without truncation or pagination, risking context window exhaustion. Critical security issue: get_api_key tool exposes credentials as a callable parameter, violating secret-injection pattern.
Add two numbers
Get the API key
Get the CommCare Connect server endpoint
Get the global stats for the given filters. Dates must be specified in YYYY-MM-DD format.
CRITICAL: get_api_key and get_ccc_server expose sensitive credentials/configuration as callable tools. This violates the secret-injection pattern. API keys should never be exposed via tools; they should be injected server-side via environment variables or vault.
get_ccc_server and get_api_key have descriptions under 20 characters (11 chars each), providing no context for LLM tool selection. Descriptions must be 10 - 1024 chars; these are too minimal.
get_ccc_server and get_api_key have empty input schemas ({}) but no documentation of return types. Output schemas must be documented so LLMs know what to expect.
get_global_stats calls requests.get() with no timeout, error handling, or validation. If the API hangs, the agent blocks indefinitely. No error recovery guidance if dates are malformed or filters invalid.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 48 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 47 | - | v1 |
get_global_stats returns raw response.json() without pagination, result truncation, or field filtering. A large result set exhausts context window and dilutes signal. The tool description mentions date format but not result limits or when pagination applies.
add tool is a mathematical utility unrelated to CommCare domain. It pollutes the namespace and forces the LLM to reason about irrelevant tools when solving CommCare tasks.
Parameter descriptions in get_global_stats say 'Optional' but do not explain validation constraints. E.g., from_date must be YYYY-MM-DD but no regex pattern or format constraint in schema. Invalid dates produce silent API errors.