Hosted multi-tenant Metabase MCP server for Claude Teams
The server registers 21 tools with complete input schemas and reasonable descriptions. All tools have descriptions (10-80 chars), and most parameters are typed with descriptions. However, descriptions are uniformly terse (under 50 chars for most tools), missing context about WHEN to use a tool vs. similar ones, and omitting prerequisites or dependencies. Output schemas are completely undocumented, no specification of what fields are returned or their types. Error handling and recovery guidance are absent from descriptions. The naming is clear and verb-driven (get_, create_, update_, delete_), but composition issues exist: multiple tools operate on overlapping concerns without clear disambiguation in their descriptions. Security patterns are partially addressed (Bearer token validation in middleware) but not reflected in tool descriptions. Overall, this is a competent but minimal implementation, suitable for a dashboard tool but lacking the polish expected for production agent integration.
Add a card to a dashboard
Copy a dashboard to a new location
Create a new card/question with a native SQL query
Create a new collection
Create a new dashboard
Delete a card/question
Delete a collection (archive it)
No output schema documentation. Tools register inputSchema but no output schema is specified in descriptions or tool metadata. LLMs cannot plan downstream calls or know what fields to expect.
Terse descriptions (10-50 chars for most tools) lack context for LLM tool selection. No explanation of WHEN to use similar tools (e.g., get_card vs. search_cards), no prerequisites, no examples of typical workflows.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | D | 59 | <=2025-11-25 | v2 |
Delete a dashboard
Get details of a specific card/question
Execute a card's query and get results
Get list of all cards/questions
Get details of a specific collection
Get items in a collection
Get list of all Metabase collections
Get details of a specific dashboard
Get list of all dashboards
Remove a card from a dashboard
Search for cards by name or description
Update a card/question
Update a collection
Update a dashboard
No error handling or recovery guidance in descriptions. Delete operations (delete_collection, delete_card, delete_dashboard) offer no confirmation flow or dry-run support, risking accidental destruction.
No pagination or result-limiting documented. Tools like get_collections, get_cards, get_dashboards may return thousands of items without limit parameters, risking context window exhaustion.
Parameter descriptions use type names without constraints. E.g., 'Collection ID' alone does not specify valid range, format, or behavior on invalid input. 'Row' and 'Col' parameters in add_card_to_dashboard have no bounds.
SQL injection risk. create_card and update_card accept native SQL queries as raw strings with no validation or sanitization noted in descriptions or implementation visible.