Plugin for managing AstrBot Skills and MCP (Model Context Protocol) servers, providing LLM tool interfaces and user commands for installation, configuration, and lifecycle management
This MCP server manages MCP servers and Skills within AstrBot, a Chinese-language bot framework. Tools are well-named with clear verbs (list_, get_, enable_, disable_, add_, update_, remove_, install_, delete_) and follow verb_noun conventions. However, quality varies significantly across tools. Most have descriptions (many in Chinese), but 4 tools (add_mcp_server, update_mcp_server, remove_mcp_server, delete_skill, install_skill, update_skill_from_zip) have minimal or generic English descriptions lacking detail about when to use them, what they return, and error recovery paths. All tools have basic input schemas with type definitions, but parameter descriptions are sparse or missing for several tools (e.g., 'args' in add_mcp_server lacks guidance on format; 'force' in install_skill lacks explanation of what security issues it overrides). Output schemas are entirely undocumented, callers cannot see what fields to expect from responses. Error handling is present in code (permission checks, validation) but descriptions do not explain error cases or recovery paths. No tool has destructive/readonly/idempotent hints. Tool composition is reasonable, separate tools for enable/disable, but install/update could benefit from clearer error messaging about what 'force' actually does.
Add a new MCP server configuration
Delete a Skill from the system
禁用指定的 MCP 服务器。需要管理员权限。禁用后将断开连接并卸载其工具。
禁用指定的 Skill。需要管理员权限。禁用后该 Skill 的指令将不会被加载。
启用指定的 MCP 服务器。需要管理员权限。启用后将连接该 MCP 服务器并加载其工具。
启用指定的 Skill。需要管理员权限。
获取指定 MCP 服务器的详细配置信息。需要管理员权限。敏感信息会被脱敏。
Install a new Skill from a ZIP file or URL with optional security scanning
Output schemas are entirely undocumented. Tools like list_mcp_servers, get_mcp_server_config, list_skills, enable_mcp_server return JSON responses (visible in code as _ok() calls), but the MCP tool definitions do not declare structured output schemas. LLMs cannot plan downstream tool calls or extract fields without knowing the response structure.
Six tools (add_mcp_server, update_mcp_server, remove_mcp_server, delete_skill, install_skill, update_skill_from_zip) have minimal or generic descriptions under 50 characters. 'Add a new MCP server configuration' and 'Remove an MCP server configuration' do not explain when to call them, what permissions are required, what happens on success, or how to recover from errors. Descriptions should be 50 - 200 chars and answer: what, when, prerequisites, side effects.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | F | 49 | 2026-07-28+ | v2 |
列出所有已配置的 MCP 服务器。返回每个 MCP 服务器的名称、激活状态和运行状态。无需管理员权限。
列出所有可用的 Skills。返回每个 Skill 的名称、描述、激活状态和来源信息。无需管理员权限。
Remove an MCP server configuration
Update configuration of an existing MCP server
Update an existing Skill from a ZIP file with security scanning
Parameter descriptions are missing or vague. 'args' in add_mcp_server lacks format guidance (is it a JSON array, a shell-quoted string?). 'force' in install_skill and update_skill_from_zip does not explain what security scan issues it overrides or the consequences of forcing installation. 'env' parameter in add_mcp_server lacks constraints (can any env vars be set?). 'zip_path' in install_skill does not specify whether it's a local file path or URL.
Error handling is present in code (permission checks return JSON errors) but descriptions do not explain error cases or recovery paths. For example, enable_mcp_server and disable_mcp_server do not mention what happens if the server name does not exist, if the user lacks admin permission, or if the connection fails. Error descriptions should tell LLMs what to do next.
No tool has tool annotations (readOnlyHint, destructiveHint, idempotentHint) in MCP definitions. Code marks risks (READ_ONLY, WRITE, DESTRUCTIVE, REVERSIBLE) internally, but these are not surfaced in the tool schema where MCP clients and LLMs can use them for safety and composition decisions.
Permission requirements are documented in descriptions (e.g., 'Requires admin permission') but not machine-readable. MCP clients cannot enforce least-privilege without explicit scope declarations. Tools that modify configuration should declare required permissions (e.g., 'scope: admin').