CakePHP MCP Server Plugin - Expose CakePHP functionality via Model Context Protocol
This CakePHP MCP server demonstrates solid foundation with 25 well-registered tools using PHP attributes and proper annotations. All tools have names, descriptions, and input schemas visible in source. Strong adherence to naming conventions (verb-first: list_, get_, cache_, run_, search_, detect_). Tool annotations (readOnlyHint, destructiveHint, idempotentHint) are correctly applied across the board. However, output schemas are not explicitly documented in the tool definitions, only inferred from implementation. Parameter descriptions are present but inconsistent in depth. Error handling exists but recovery guidance is sparse. No secrets exposed as parameters (good). Descriptions average ~80-150 chars, which is below the 194-char baseline for A+ tools. Several parameter constraints are documented but some critical tools lack examples of expected behavior.
Clear all entries from a CakePHP cache configuration
List all configured CakePHP cache configurations with engine information
Delete a key from a CakePHP cache configuration
Read a value from a CakePHP cache configuration by key
Write a string value to a CakePHP cache configuration
Read a specific application configuration value; sensitive keys are redacted
Inspect available database connections, including the default connection
Output schemas not explicitly documented in tool definitions. Return types are inferred from implementation but not formally stated in tool metadata. This forces LLMs to discover response structure through trial or assumes they understand CakePHP internals.
Two tools (system_info, debug_status) have empty or missing descriptions. This violates the critical check that every tool must have a non-empty, meaningful description.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 69 | 2026-07-28+ | v2 |
Read database schema for tables, columns, constraints, and indexes
Detect potential route collisions and conflicts
Get statistics about the indexed documentation
Get detailed information about a specific CakePHP console command
Get full content of a documentation file by document ID
Get detailed information about a specific named route
List all available CakePHP console commands with optional filtering and sorting
List available environment variable names with all values redacted
List all registered routes with optional filtering and sorting
List all available log files in the application logs directory. Returns an empty array when no .log files exist or when the application uses non-filesystem logging (database, syslog, etc.).
Read the last N lines from a log file, optionally filtered by log level. Use log_list to discover available files.
Find which route matches a given URL path
Describe a CakePHP ORM Table: associations, behaviors, display field, primary key, entity class
Run a find query on a CakePHP ORM Table. Type must be 'all', 'first', or 'count'.
Run a registered CakePHP console command. Use list_commands to discover available commands. Only commands registered in the application command collection can be executed.
Search CakePHP documentation using full-text search with relevance ranking. Results are sorted by relevance (best first) with scores where higher = more relevant.
Error handling varies across tools. Cache tools have assertConfigured() that throws ToolCallException with helpful context, but other tool categories (CommandTools, DatabaseTools, etc.) do not show defensive input validation or recovery guidance in visible code. Log and route tools may silently return empty results instead of guiding the agent.
Parameter constraints lack explicit enum or range documentation in several tools. E.g., orm_find 'type' accepts 'all', 'first', or 'count' (documented in description), but no enum constraint visible. log_read 'lines' is unbounded, no min/max specified. search_docs 'limit' mentions default:10, max:50 but no minimum stated.
Response field naming consistency. Several tools return generic field names (e.g., 'found' in cache_read, 'deleted' in cache_delete) but other tools lack explicit field documentation. If downstream tools need to compose results, mismatched naming will force LLMs to reason about field mappings.
Pagination not implemented for list-returning tools. list_commands, list_routes, log_list, docs_stats do not document or enforce pagination limits. Large result sets (50+ items) risk exhausting context window. No limit parameter visible in list_commands or detect_route_collisions, creating unbounded result risk.