CLI tool and framework for defining, developing, and shipping AI agent skills
This MCP server defines 4 tools (read, write, edit, bash) with basic input schemas and descriptions. However, the definitions fall significantly short of production quality. All tool descriptions are extremely brief (10-30 characters), providing minimal context for LLM selection. Parameter descriptions are present but sparse. Output schemas are not documented anywhere in the provided source code. The tools combine multiple concerns (read with offset/limit pagination) and lack proper error handling guidance. The bash tool in particular presents severe security risks with no mention of input validation, rate limiting, or execution safeguards. As a STDIO-only transport, this server is capped at 50 maximum regardless of definition quality, but the definitions themselves would score in the 30-40 range even on HTTP.
Execute bash shell commands
Edit a file by replacing exact text content
Read file content with optional offset and limit
Write content to a file
All tool descriptions critically short (10-30 chars). Descriptions must be 50-200 characters to provide sufficient context for LLM selection. Current descriptions lack WHAT the tool does, WHEN to use it, and what it returns.
No output schemas documented for any tool. LLMs cannot plan downstream calls or structure their reasoning without knowing what fields these tools return. Must document return types and field names.
bash tool exposed without security guardrails: no input validation, no command injection prevention, no timeout documentation, no rate limiting. Executing arbitrary shell commands is irreversible and high-risk.
No error handling guidance. Tools provide no recovery instructions when they fail. LLM has no way to know if a failure is retryable, user-fixable, or fatal.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | F | 43 | 2026-07-28+ | v2 |
read tool combines pagination logic (offset, limit) without documenting total result count, whether more results exist, or how to iterate. LLMs cannot discover when pagination is exhausted.
Parameter descriptions are minimal (2-5 words). 'Optional byte offset to start reading from' is adequate, but lacks format/range constraints. No explanation of interaction between offset, limit, and file size.
write and edit tools do not document what happens on path conflicts, file permissions issues, or disk full scenarios. No guidance on idempotency or retry safety.
edit tool requires exact oldText match with no fuzzy matching or context tolerance. Error messages must explain what text was not found and suggest alternatives.
bash tool timeout parameter exists but lacks documented default, minimum, and maximum values. LLM has no guidance on appropriate timeout windows.
No permission-gating or audit trail. Tools that modify filesystem state (write, edit, bash) do not log who called them, when, with what parameters, or what outcome.