MCP server for managing courses/lessons with database storage, search, and upload capabilities
cours-mcp has 2 tools with visible schema definitions and descriptions, but significant quality gaps. Both tools have basic descriptions (59-67 chars) that fall short of the 194-char average for production tools. The input schemas are present and properly typed, but parameter descriptions are minimal. The tool names follow verb_noun convention (rechercher_cours, ajouter_cours) but lack clarity about French vs English naming consistency. Most critically, neither tool has documented output schemas, error handling guidance, or recovery paths. The rechercher_cours tool lacks pagination support for results (LIMIT 10 is hardcoded, no offset/page params). The ajouter_cours tool has no dry-run or confirmation step despite being destructive. Database connection handling is present but error responses are unstructured (plain TextContent with no recovery guidance). No tool annotations (readOnlyHint/destructiveHint/idempotentHint) are present. Per the hard rules, this prevents scores above 50 for individual tools since output schemas are not documented.
Ajoute un nouveau cours ou exercice
Recherche dans vos cours par mot-clé
No output schema documented. LLMs cannot predict response structure or chain tools. rechercher_cours returns TextContent with unstructured markdown; ajouter_cours returns a success message but no object schema.
Minimal parameter descriptions. rechercher_cours has only 'Mot-clé à rechercher dans vos cours' (40 chars); ajouter_cours type_contenu lacks description entirely ('Type de contenu' is 16 chars, below minimum 20 char threshold). LLMs cannot infer usage without fuller context.
No pagination support. rechercher_cours hardcodes LIMIT 10 with no offset/page parameters. Large result sets will be truncated without LLM visibility or ability to fetch more.
No error handling or recovery guidance. Database errors (connection failures, constraint violations, duplicates) return raw exceptions as TextContent. LLMs have no actionable recovery path.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 35 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 29 | - | v1 |
Missing tool annotations. Neither tool declares readOnlyHint (rechercher_cours is read-only) or destructiveHint (ajouter_cours modifies state). Without these, LLMs cannot reason about safety or side effects.
ajouter_cours lacks confirmation or dry-run. This is a destructive write operation with no safeguard. An LLM error could insert hundreds of duplicate courses.
Database credentials hardcoded in config.py example. While marked as example, the pattern invites secrets in config. No mention of environment variable injection or vault integration.
SQL injection vulnerability. Both tools use parameterized queries (good), but input validation is absent. No checks on mot_cle length, titre length, or contenu size. LLMs could pass enormous strings causing DoS.
No rate limiting. Agents could invoke ajouter_cours thousands of times per minute without throttling, filling the database or hitting resource limits.
Tool name inconsistency: French names (rechercher_cours, ajouter_cours) mixed with likely English-speaking agent base. No clear naming convention applied across potential future tools.