MCP server that scrapes tutorial content, generates bash scripts using OpenAI, and executes them on remote servers via SSH
This MCP server has severe definition quality issues. The single tool 'execute_tutorial_script' lacks proper error handling documentation, has a vague description that doesn't explain prerequisites or consequences, and no output schema is documented. The tool combines multiple high-risk operations (web scraping, LLM-based code generation, remote SSH execution) without any safety guardrails, confirmation steps, or clear error recovery guidance. The input schema is minimal (only a URL string), but critically lacks validation constraints, format specifications, or guidance on what constitutes a valid tutorial URL. The tool description does not clearly state that it executes arbitrary bash commands on a remote server, a critical security and safety consideration. No parameter constraints, no error classification, no recovery guidance.
Receives request to execute tutorial script from URL. Scrapes tutorial content, generates bash script using LLM, and executes on remote server
Tool combines destructive operations without safety warnings. Description does not mention that the tool executes arbitrary bash code on a remote server via SSH. This is DESTRUCTIVE, not mentioned in the description.
No output schema documented. The function returns a plain string 'OUTPUT:\n{output}\n\nERROR:\n{error}' but LLMs have no structured understanding of the response format, fields, or what to expect. This violates the pattern of documenting output structure.
No error handling guidance or recovery patterns. If SSH fails, LLM receives raw exception. If script generation fails, no guidance on retry or alternative. No categorization of errors as retryable vs fatal.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 30 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 23 | - | v1 |
Input parameter 'url' lacks validation constraints. No format specification, no allowed domain restrictions, no guidance on what constitutes a valid tutorial URL. Description is only 91 characters and vague: does not explain prerequisites (SSH setup required), does not state consequences (code execution on remote system).
Tool name is ambiguous. 'execute_tutorial_script' does not clearly convey that it scrapes URLs, generates code via LLM, and executes on remote SSH hosts. A clearer name would be 'execute_remote_generated_script_from_url' or broken into separate tools (scrape_tutorial, generate_bash_from_content, execute_script_on_remote).
No confirmation/dry-run step for irreversible operations. The tool directly executes bash commands on a remote server. Per the confirmation-request pattern, destructive tools should support a dry-run or require explicit confirmation, especially when code is LLM-generated and unreviewed.
SSH credentials (SSH_HOST, SSH_USER, SSH_KEY_PATH) are hardcoded as module-level config variables with empty placeholders. While not passed as tool parameters (which is correct per secret-injection), the code comment 'SSH_HOST = ""' indicates incomplete setup. More critically, there is no guidance in the description that SSH credentials must be configured beforehand.
No permission checks or scope declarations. The tool blindly executes whatever the LLM-generated script contains. There is no validation that the script is safe, no sandboxing, no limit on what commands can run. This violates the permission-gate pattern.
LLM script generation is unreliable and dangerous. The prompt 'Extract only shell commands...' is vague and provides no safety guardrails. The LLM could hallucinate destructive commands (rm -rf /, > /dev/zero, etc.). No validation of generated script before execution.
Web scraper has no depth/size limits. The recursive scrape_all_links_and_content() function could crawl thousands of pages, consuming massive bandwidth and time. No timeout, no page limit, no exit condition beyond 'visited set' size.