Analyze and score supply chain disruption risk for e-commerce operations. Evaluates geographic concentration risk, single-source dependency, supplier reliability, lead time variance, and inventory buffer adequacy.
The server exposes a single tool 'analyze' with moderate quality. The tool has a clear description (~145 chars) and a structured input schema with multiple parameters. However, there are significant gaps: (1) the input schema is defined in docstring form only, not as formal JSON Schema visible in tool registration; (2) parameter descriptions are embedded in the docstring, making them inaccessible to MCP protocol consumers; (3) the output schema is described in prose but not formally documented; (4) the tool lacks error handling guidance and recovery hints; (5) parameter type definitions exist but are not enforced; (6) no tool annotations (readOnlyHint, destructiveHint, idempotentHint) are present; (7) the implementation resides in client.py, suggesting this is an SDK wrapper rather than a true MCP server with proper tool registration.
Run full supply chain risk analysis. Evaluates geographic concentration risk, single-source dependency, supplier reliability, lead time variance, and inventory buffer adequacy.
Tool definition not registered via MCP protocol. Tool exists in client.py as a Python method, but no evidence of MCP tool registration with schemas, descriptions, and input definitions. Source code shows a Python SDK class, not an MCP server exposing tools to the protocol.
Input schema not formally structured. The 'suppliers' parameter requires a list[dict] with nested fields (name, country, lead_time_days, reliability_score, category), but the schema is only documented in the docstring. No JSON Schema definition is visible in the source code; parameter validation is implicit in the implementation.
Output schema not formally documented. The tool returns a dict with keys risk_score, risk_level, risk_factors, recommendations, supplier_count, inventory_days. The structure of risk_factors (list of dicts with factor, score, weight, recommendations) is inferred from code, not documented in an output schema definition.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | F | 49 | 2026-07-28+ | v2 |
No error handling guidance. The tool returns a hardcoded response when suppliers list is empty, but there is no classification of errors (retryable, user-fixable, fatal) and no recovery hints for the LLM when analysis fails or produces unexpected results.
Parameter descriptions buried in docstring. The MCP protocol layer cannot parse parameter metadata from Python docstrings. Each parameter (suppliers, inventory_days, single_source_categories) should have formally declared descriptions in the tool schema, not in inline code comments.
No tool annotations. The 'analyze' tool is read-only and idempotent (multiple calls with the same input produce the same output), but these hints are not declared via readOnlyHint or idempotentHint attributes in the tool definition.
Missing enum constraints for categorical inputs. The 'category' field within suppliers list accepts free-form strings; no enum of valid categories is provided. The implementation references predefined risk levels (Low, Moderate, High, Critical) but these are hard-coded in RISK_THRESHOLDS rather than exposed as parameter constraints.
No validation feedback for invalid inputs. The tool does not validate that reliability_score is in [0.0, 1.0] range, that country codes are valid ISO 2-letter codes, or that lead_time_days is positive. Invalid inputs silently produce incorrect risk scores rather than failing with actionable error messages.