Multi-demo repository showcasing CapiscIO Agent-to-Agent (A2A) security patterns, including enforcement demos, policy-based access control, and multi-agent frameworks (CrewAI, LangChain, LangGraph) with badge-based authentication.
This repository is a collection of MCP server DEMONSTRATIONS, not a single production MCP server. It contains 11 tools scattered across multiple demo scripts (enforcement-demo, multi-agent-demo with crewai-agent and langchain-agent variants), with significant quality and structural issues. Tool definitions are inferred from demo code rather than registered via a formal MCP server framework. Many tools lack proper schemas, descriptions are minimal or missing, and there is no centralized tool registry or transport layer. The repository demonstrates how to build agents using CapiscIO SDKs but does NOT implement a cohesive MCP server that would be remotely callable.
Evaluate a mathematical expression.
Cancel all pending orders. Requires a valid badge.
Cancel all pending orders. Requires a valid badge.
Enhance and polish written content
Get the current UTC time.
Look up the price of a product by SKU.
Look up the price of a product by SKU.
Tools are scattered across multiple demo scripts with no centralized MCP server registration. Tool definitions are inferred from agent framework code (CrewAI, LangChain) rather than registered with an MCP server. This violates the pattern:tool requirement for explicit, discoverable tool registration.
No visible input schemas in the provided source code. Parameter definitions exist inline in demo code (e.g., 'sku', 'quantity') but are not formally declared as JSON Schema objects with type, description, and constraint metadata.
Duplicate tool names appear 3 times: get_price (appears twice), place_order (appears twice), cancel_all_orders (appears twice) across different demo files. LLMs will conflate these, no clear distinction of intent. Violates naming:distinguish-similar-tools.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 54 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 36 | - | v1 |
Place an order for a product. Requires a valid badge.
Place an order for a product. Requires a valid badge.
Search the web for information about a topic.
Search the web for information about a topic.
Descriptions are minimal (30 - 60 chars) and lack actionable guidance. E.g., 'Search the web for information about a topic' does not explain WHEN to call this vs. other search tools, what format the response is, or how to interpret it. Baseline for A+ tools is 50-200 chars with purpose, preconditions, and expected output.
Parameter 'content' in enhance_writing is under-described ('Content to write/process'). It does not specify: max length, expected format (plain text, markdown, HTML?), character encoding, or failure modes if content is too large or malformed. Violates pattern:tool-description.
No output schemas documented for ANY tool. The rubric requires 'Document the output schema. LLMs need to know what fields to expect.' Without this, downstream tool chaining is difficult and error-prone. E.g., get_price should document 'returns {price: number, currency: string, sku: string}' or similar.
place_order and cancel_all_orders are DESTRUCTIVE/WRITE operations with no error handling guidance or confirmation step. Agents could accidentally cancel all orders or place duplicate orders on retry. Violates pattern:confirmation-request and pattern:error-classification.
'Requires a valid badge' is mentioned in place_order and cancel_all_orders descriptions but no badge parameter exists. This is unclear, is the badge implicitly passed, or should it be a parameter? This violates pattern:tool-description (incomplete, ambiguous descriptions).
No pagination, result limits, or batching for search_web, enhance_writing, or other tools that might return large responses. Without limits, LLMs risk exhausting context windows. Violates pattern:paginated-result.