Local MCP server that exposes selected AWS audit scripts as explicit tools.
This server defines 4 tools with mixed quality. All tools have names and descriptions, but parameter quality varies significantly. Two tools (aws_region_audit, s3_cloudwatch_report) have well-structured input schemas with type definitions, constraints, and descriptions. Two tools (list_recent_reports, read_report_summary) appear to be inferred from Java backend code rather than directly visible in the MCP TypeScript source, which limits confidence in their actual schema implementation. Output schemas are entirely undocumented, there is no evidence of what these tools return, making it impossible for LLMs to plan downstream composition. Error handling and recovery guidance are absent. The server invokes shell workflows and backend services, which is appropriate for a local audit tool, but lacks the polish needed for production agent use.
Invokes the local MCP-backed AWS regional audit shell workflow.
Lists recent audit or S3 CloudWatch report directories under the local reports tree.
Reads a report bundle under the local reports tree and returns summary data plus a short text preview.
Invokes the local MCP-backed S3 CloudWatch shell workflow.
Output schemas entirely undocumented. No evidence of return types, field names, or structure for any of the 4 tools. LLMs cannot plan downstream composition or extract values for chaining.
Two tools (list_recent_reports, read_report_summary) are inferred from Java backend code in LlmToolPlannerService.java, not directly visible in the TypeScript MCP registration. Cannot verify actual parameter schema implementation or tool registration details in mcp/src/index.ts.
No error handling or recovery guidance. If a tool fails (e.g., region not found, bucket inaccessible, directory missing), the LLM receives no direction on retry strategy, alternatives, or user-fixable issues.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | D | 58 | 2026-07-28+ | v2 |
Tool descriptions lack actionable context. 'Invokes the local MCP-backed AWS regional audit shell workflow' does not explain when to use this vs other audit tools, what the typical next step is, or what data is returned. Descriptions range 34 - 72 chars, below the 50 - 200 baseline for LLM optimization.
Parameter descriptions are minimal. 'optional region filter. When omitted, the shell script uses its defaults' is vague, does omitting it auto-detect, use all regions, or fail? 'optional service filter using the MCP-supported audit service keys' does not list the keys. LLMs need explicit enum constraints or discovery tools.
No tool composition chain visible. If aws_region_audit returns findings, how does list_recent_reports discover them? If read_report_summary returns a directory path, what fields does it include? Tool interfaces are not designed for agent chaining.