Static source inference · medium confidence · detected: Logging
Deprecated protocol patterns detected
Summary
This server has significant definition quality gaps. While tool names follow verb_noun conventions well (get_nodes, get_node_status, execute_vm_command), descriptions are present but lack LLM-optimized detail. Input schemas are visible and typed, but descriptions for parameters are minimal or missing context. The execute_vm_command tool presents a critical security concern by accepting arbitrary shell commands without validation guidance. Output schemas are not documented. Error handling is absent, no recovery guidance, no categorization of retryable vs. fatal errors. The server lacks pagination support despite potentially returning large lists (e.g., get_vms, get_containers). Tool composition is reasonable but could be optimized (e.g., get_node_status could include per-tool filtering).
Tools (7)
execute_vm_commandwriteauthsource verified62/100
Execute a shell command inside a virtual machine via QEMU guest agent
execute_vm_command accepts arbitrary shell commands without input validation, sanitization guidance, or constraint documentation. Description does not warn about command injection risks or require confirmation for destructive operations.
No output schemas are documented for any tool. LLMs cannot predict response structure, plan downstream calls, or extract required fields for chaining. This violates the documented-return-types baseline (100% of A+ tools).
No pagination support (limit, offset, page_size, cursor) on tools that return lists (get_nodes, get_vms, get_containers). Large result sets will exhaust context window and degrade LLM reasoning.
get_nodesget_vmsget_containersget_storage
Recommendations
Add output schema documentation for all 7 tools. For get_vms, document: 'Returns an array of VM objects, each with fields: vmid (int), name (str), status (str: running|stopped), node (str), memory_mb (int), cores (int), uptime_seconds (int).' Include per-item field descriptions.
Example for get_vms: 'List all virtual machines (QEMU/KVM) in the cluster, including status, resource allocation, and node location. Returns up to 50 VMs; use pagination for larger clusters. Call this to discover available VMs before executing commands.'
Add pagination parameters (limit, offset) to list tools. Example: get_vms(limit: int [default=20, min=1, max=100], offset: int [default=0]). Return a response with {vms: [], total: int, returned: int} to support discovery of large clusters.
For execute_vm_command, add a confirmation step: require a dry_run=true parameter first, return simulated output, then ask user to confirm. Alternatively, gate commands behind an allowed-list (whitelist of safe commands like 'uname', 'whoami', 'systemctl status') and reject dangerous patterns (rm -rf, shutdown, reboot without specific flags).
Document parameter constraints in descriptions. For execute_vm_command.vmid: 'VM ID (positive integer, 100-999999). Call get_vms first to discover valid IDs.' For execute_vm_command.command: 'Shell command to execute in the guest. Allowed commands: systemctl, service, ps, netstat, journalctl. Dangerous patterns (rm -rf, shutdown -h, reboot) are blocked.'
Add error handling to all tools. Example: 'If node not found: return {error: "Node 'pve1' not found", available_nodes: ["pve1", "pve2"], next_step: "Call get_nodes() to list available nodes."} with HTTP 404.' Document this in the tool description or a dedicated error_handling section.
Spec posture evidence
Inferred effective spec: <=2025-11-25.
Relies on Logging (deprecated) - log to stderr or use OpenTelemetry
Score history
Overall score trend
First recorded score · v2 rubric
59/100
Scored
Grade
Overall
Spec posture
Rubric
2026-09-23
D
59
<=2025-11-25
v2
List all virtual machines across all nodes in the cluster
Parameter descriptions are minimal or context-free. 'Name/ID of node to query' in get_node_status lacks format guidance, constraints, or examples of valid node identifiers. Parameter descriptions average under 50 chars; baseline is 72 chars.
No error handling or recovery guidance. Tools do not categorize errors as retryable, user-fixable, or fatal. No actionable error messages. LLMs have no guidance on what to do if a call fails.
execute_vm_command is a WRITE operation but has no confirmation step or dry-run capability. This violates the confirmation-request pattern for irreversible operations. An LLM could accidentally execute destructive commands.
execute_vm_command
Add tool risk annotations if supported by the MCP framework. Mark execute_vm_command with destructiveHint: true so clients can flag it in logs and audit trails.
Strip unnecessary API metadata from responses. Return only fields agents need: {vmid, name, status, node, memory_mb, cores}. Omit uptime_ms, description, machine type, BIOS info, etc. This reduces token count and keeps responses focused.
For get_node_status, include common follow-up fields (e.g., list of VMs on that node, storage pools attached, network interfaces). This avoids forcing the agent to make additional calls to get_vms and filter by node.
Document when tools are safe to retry. Mark read-only tools (all except execute_vm_command) as idempotent. Mark execute_vm_command as non-idempotent with guidance: 'Do not retry automatically; ask user before retrying, as the command may have executed partially.'