MCP server that executes GraphQL queries and mutations against an e-commerce API, providing product management operations including fetching products by ID, listing all products, and adding new products
Single tool 'execute-graphql' with adequate naming and description but significant schema and composition issues. The tool accepts free-form GraphQL query strings, which bypasses structured input validation and forces LLMs to construct GraphQL syntax without schema-level guardrails. Parameter descriptions exist but lack constraint details. No output schema is documented. Tool conflates multiple distinct operations (addProduct, getProductById, getAllProducts) into one generic executor, violating single-responsibility principle. Error handling returns generic text responses rather than actionable guidance. The server demonstrates basic MCP structure but lacks production-grade tool design patterns.
Execute a custom GraphQL query or mutation against the e-commerce server. Available operations: - Mutation: `addProduct(input: ProductInput!)` - Adds a product. Returns `{ message }`. - Input: `ProductInput` requires `name: String!`, `price: Float!`, `category: String!`; optional `description: String`, `stock: Int`. - Query: `getProductById(id: ID!)` - Fetches a product by ID. Returns `{ _id, name, description, price, category, stock }`. - Input: `id: ID!` (required). - Query: `getAllProducts` - Fetches all products. Returns `[{ _id, name, description, price, category, stock }]`. - Input: None. Use these operation names and input structures in your GraphQL query string.
Tool combines multiple unrelated operations (addProduct, getProductById, getAllProducts) into a single generic GraphQL executor. LLM must construct raw GraphQL query strings without structured input guidance.
No documented output schema. Tool returns raw JSON with no field descriptions, data types, or structure guidance. LLMs cannot plan downstream operations.
Query parameter description lacks constraint details. Does not explain valid GraphQL syntax, required operation names, or what queries will fail. Invites malformed queries.
Error handling returns generic text messages ('GraphQL execution failed: ...') instead of actionable recovery guidance. No error classification (retryable vs fatal).
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 54 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 42 | - | v1 |
Variables parameter is optional with minimal description. No guidance on expected variable names, types, or relationship to query fields.
Tool exposes raw GraphQL resolution without input sanitization. LLM-constructed queries could trigger unintended mutations or expose sensitive data if resolver permissions are not carefully gated.