Model Context Protocol server for StarRocks database
This MCP server has fundamental definition quality gaps. All 5 tools are registered with schemas and basic descriptions, but several critical issues emerge: (1) Parameter descriptions are minimal or absent, most parameters lack guidance on format, constraints, or expected values. (2) Output schemas are completely undocumented, no indication of what fields the agent will receive, their types, or relationships. (3) Error handling is generic (catch-all Exception → TextContent) with no actionable recovery guidance for the agent. (4) Three tools (write-query, create-table, read-query) accept raw SQL strings with minimal validation, creating SQL injection risk and producing unstructured plaintext output. (5) Tool descriptions lack context for when to use them or what to expect. The server does implement a readonly mode and basic permission checks, which is positive, but the overall definition quality is below the median for community servers.
Create a new table in the StarRocks database
Describe the schema of a specific table in the StarRocks database
List all tables in the StarRocks database
Execute a SELECT query on the StarRocks database
Execute an INSERT, UPDATE, or DELETE query on the StarRocks database
No output schemas documented for any tool. Agent cannot infer response structure, field names, or types. All tools return unstructured TextContent(text=str(results)), which requires LLM to parse Python repr() output.
Parameter descriptions are generic or missing. 'query' parameter in read-query, write-query, create-table lacks guidance on format, constraints, SQL syntax, or max length. LLM cannot infer valid input.
No error handling guidance. Generic catch-all Exception handler returns 'Error: {str(e)}' with no actionable recovery path. LLM receives raw exception messages (e.g., 'ProgrammingError: syntax error') and cannot self-correct.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 40 | - | v1 |
SQL injection risk not addressed in descriptions. read-query, write-query, create-table accept raw SQL strings. No mention of parameterized queries, input validation, or safe SQL construction in tool descriptions or schema.
Unstructured output format. All tools return Python repr() output (str(results)) as plain text. Agent must parse 'Row(name=...) Row(name=...)' instead of receiving JSON-serialized structured objects with clear field names and types.
Tool descriptions do not clarify permission/read-only mode behavior. write-query and create-table descriptions do not warn agent that these tools may be unavailable in readonly mode. Agent will attempt the call, hit a permission error, and waste a turn.
read-query enforces SELECT-only check at runtime (ValueError if not SELECT) but description does not clearly state this constraint. LLM may attempt UPDATE/DELETE and fail.