MCP server for processing CSV and Excel files with LLM integration using Spring Boot
Single tool 'process-file' has critical definition gaps. Tool name lacks clarity on what 'process' means in the context. Description is generic and does not guide LLM selection. Input schema shows parameter types (MultipartFile, string) but lacks descriptions for parameters and no output schema is documented. The tool accepts a file and a user prompt, sends to LLM for 'analysis', but the response structure is completely undocumented. This forces the LLM to guess what it will receive. No error handling guidance, no examples of expected output format, no pagination or result limits defined. The server has no prompts, resources, or proper tool composition support.
Processes CSV or Excel files and sends their content to an LLM service for analysis based on a user-provided prompt
Tool name 'process-file' is generic and ambiguous. Does not start with a clear action verb. 'process' conveys no specific intent, could mean parse, validate, transform, analyze, or format. LLMs cannot disambiguate this from similar tool names.
Tool description 'Processes CSV or Excel files and sends their content to an LLM service for analysis based on a user-provided prompt' is vague. Does not explain WHEN to use this tool, what output is returned, what analysis means, or what formats the LLM returns (text? JSON? structured data?). Blocks LLM selection confidence.
Input parameter 'file' (MultipartFile) has no description. Input parameter 'prompt' (string) has no description. LLM cannot infer constraints: Is file size limited? Which MIME types are accepted (CSV, XLS, XLSX)? What prompt format is expected? Constraints must be explicit in parameter descriptions.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 34 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
No output schema is documented. The tool returns LLM analysis response, but the structure is unknown. Is it a text string? JSON with fields? Plain text summary? Nested structure? LLM cannot plan downstream tool calls or extract required data without knowing response format.
No error handling or recovery guidance. If file upload fails, LLM receives no instruction on retry strategy or alternatives. If LLM service is unavailable, no fallback is suggested. Pattern: recovery-guide missing.
No file size limit, timeout, or rate limit documented. Tool accepts arbitrary files without stated constraints. An LLM could be tricked into uploading multi-gigabyte files, exhausting resources or causing timeouts.
Tool delegates to external LLM service but credentials/API keys are not mentioned as being injected server-side. If they are passed as parameters (not visible in provided code), this is a critical security leak. If they are hardcoded or injected, clarify this in documentation.