MCP server for Laravel Dashboard CMS providing tools for content management, module control, email templates, site health monitoring, and daily briefings
Laravel Dashboard MCP server has 14 tools with consistently present descriptions and clear naming. However, the implementation shows significant gaps in schema completeness, parameter validation, and error handling. All tools use action-verb naming (activate-, assign-, attach-, clear-, create-, deactivate-, delete-, generate-, get-, list-) which is good practice. Descriptions range from 48-340 characters, mostly in the acceptable 50-200 char range. However, parameter descriptions are often minimal or generic (e.g., 'Module folder or JSON name' without format constraints), and output schemas are entirely undocumented, LLMs cannot infer what list_modules returns or what structure get_post provides. Critical patterns missing: no error recovery guidance, no documented output schemas, no per-parameter type validation hints, no idempotency guarantees for write operations. Risk indicators properly labeled (WRITE, DESTRUCTIVE, READ_ONLY) but not surfaced as tool annotations.
Enable (activate) an installed module. Runs migrations and publishes assets by default. Use list-modules to find module names. Requires Superadmin.
Assign categories and/or tags to a post by term ID. Replaces existing terms for the given taxonomies. Use list-terms first to discover term IDs.
Set the featured image on an existing post using a media library ID or URL. Use list-media to find available media.
Clear application caches (config, route, view, and application cache). Use after settings or module changes.
Create a new post or page with LaraBuilder blocks. Use topic for full AI generation, or title/content for manual creation. Generates at least one header image by default when OpenAI is configured.
Output schemas not documented. LLMs cannot plan downstream calls without knowing what fields each tool returns. E.g., what does list-modules return? What are the field names in get-daily-briefing response? This prevents proper tool composition.
Missing error recovery guidance. Destructive tools (delete-post) and write operations (create-post, activate-module) lack actionable error messages. E.g., what happens if a module dependency is unmet? What can the LLM do to recover?
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 65 | 2026-07-28+ | v2 |
Disable (deactivate) an installed module. Use list-modules to find module names.
Permanently delete a post or page. Use to remove drafts or unwanted content.
Generate SEO meta title and description for an existing post.
Get a personalized today checklist with actionable items from core and installed modules — tickets, reviews, form messages, errors, and more. Use when the user asks what is up, what needs attention, or what to do today.
Retrieve a single email template by ID, optionally with rendered preview content.
Read the last N lines from a storage log file. Use list-logs first to discover available log paths.
Retrieve a single post or page by ID.
Read-only site snapshot: Laravel version, drivers, MCP status, and installed modules. Use to diagnose missing tools or configuration issues.
List email templates with optional search, type filter, and pagination.
Parameter validation constraints underdocumented. E.g., create-post 'tone' enum is visible but image_count range (1-3) is only in description text, not enforced by schema. Per-parameter format hints (regex, min/max) missing for natural language fields.
No tool annotations. Risk labels (WRITE, DESTRUCTIVE, READ_ONLY) are metadata but not surfaced as MCP toolAnnotations (readOnlyHint, destructiveHint). LLM clients cannot auto-gate dangerous operations.
No pagination limits documented for list tools. list-email-templates accepts per_page up to 50 and supports page, but get-daily-briefing 'sections' array is unbounded. LLMs may request excessive data, blowing context windows.
Permission requirements not declared. activate-module requires Superadmin, but no other tools document their permission gates. This prevents least-privilege agent configuration and clear audit trails.
Idempotency not guaranteed for write operations. create-post, assign-post-terms, and delete-post lack idempotency statements. If an agent retries due to timeout, duplicate posts or duplicate term assignments may occur.
Discovery tools underdocumented. list-modules is referenced by activate-module but not defined in the tool list. Same for search_users, find_channels, LLMs cannot discover what lookup tools exist.