MCP server for generating and managing e-commerce sales data with MySQL database integration. Provides tools for creating/deleting products and users, and resources for fetching products, users, and categories from the database.
This server has critical definition quality gaps across all three tools. The source code provided is truncated, preventing full verification of schema completeness. Resource definitions are present but incomplete. Error handling is absent, no guidance on retryability, user-fixable errors, or recovery paths.
Creates a new product in the database.
Creates a new user in the database.
Deletes a product from the database by name.
Tool descriptions are critically short (13-24 chars). LLMs cannot determine when or why to select these tools.
Output schemas are completely undocumented. No specification of return types, fields, structure, or format. LLMs cannot plan downstream operations or extract relevant data.
delete_products lacks any confirmation, dry-run, or pre-execution validation. This is a destructive operation (marked DESTRUCTIVE risk) with no safeguards against accidental cascading deletes.
create_users accepts 'password_hash' as a parameter. This is a security risk, credentials must never appear as tool parameters. Implement server-side hashing and accept plaintext passwords only (or better, use OAuth/SSO).
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | D | 51 | 2026-07-28+ | v2 |
Parameter descriptions are missing or trivial for all tools. Rubric baseline: 100% of A+ tool params have descriptions. Example: 'password_hash' lacks guidance on format (bcrypt? SHA256? plain text?), length, or encoding.
No error handling documentation. What happens if a product name is duplicated? What if category_id doesn't exist? What if a user already exists? LLMs get no recovery guidance.
delete_products accepts only 'name' parameter. Products should be deleted by product_id (system identifier), not by name (user-friendly but ambiguous if duplicates exist). No safeguard against unintended cascade deletes across foreign-key-dependent order_items.
Resource definitions (get_products, get_selected_product) are truncated in source. Cannot verify URIs, return schemas, or whether they properly document what data they expose.
No input validation hints in parameter descriptions. Example: 'price' parameter has no min/max range stated (can it be negative? zero?). Rubric baseline: 'Specify minimum and maximum for numeric parameters.'
create_users parameter 'username' has no description of format constraints (min/max length, allowed characters, uniqueness). Database schema shows UNIQUE constraint but tool description does not warn about duplicate username errors.