Rails Hyperdrive MCP server. Prefer locate_source/list_models before guessing.
Rails Hyperdrive is a well-engineered MCP server with 8 tools covering Rails introspection and code execution. All tools have clear, action-oriented names (run_, list_, describe_, lookup_, locate_, tail_) and descriptions between 80-150 characters. Input schemas are present and properly typed for all tools. However, several parameters lack descriptions, output schemas are not documented, and error handling guidance is minimal. The server demonstrates good naming discipline (verb_noun pattern) and appropriate risk classification (7 read-only, 1 irreversible). No tool definitions were inferred, all are explicitly registered in spec/hyperdrive/tools_spec.rb.
Snapshot of Rails/Ruby/DB versions plus the app's direct gem dependencies and installed gem skills.
Describes every ActiveRecord model's table, columns, validators, and associations with error resilience.
Lists all Rails application routes with HTTP methods, paths, and controller actions.
Resolves constant references, class/instance methods, and gem dependencies to their source file locations.
Returns documentation for Ruby constants, methods, and classes from YARD and stdlib.
Evaluates Ruby code in the running Rails application context with timeout and exception handling.
Output schemas not documented. Tools return JSON (describe_app, run_ruby, run_sql) but the response field structure and types are not specified in the schema.
No error recovery guidance. Tools like run_ruby and run_sql can fail (timeouts, syntax errors, access denied) but descriptions do not advise the LLM on next steps (e.g., 'Try with a simpler query' or 'Increase timeout').
Critical security issue: run_ruby tool is IRREVERSIBLE and evaluates arbitrary Ruby code in the running Rails app context. No dry-run, no confirmation step, no whitelist of safe methods. Description does not warn of destructive capability or mention dev-only restriction.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 79 | 2026-07-28+ | v2 |
Executes read-only SELECT queries against the application database with result capping and tab-separated output.
Returns trailing lines from the Rails application log file with path escaping protection.
Parameter descriptions incomplete or missing. 'lines' param in tail_logs lacks min/max bounds. 'timeout' in run_ruby mentions clamping but not the actual range or units in the description itself (only in code).
list_models and list_routes return unbounded lists. No pagination, no limit parameter, no total count in response. A large Rails app could return hundreds of routes or models, blowing the context window.
Tool descriptions do not state when to call them relative to similar tools. 'locate_source' and 'lookup_doc' both operate on constants/methods, the description should explain when to use each (e.g., 'Use locate_source to find where code is defined; use lookup_doc to read its documentation').