Collection of MCP server demos for testing and security scanning: calculator, filesystem, notes, SQLite, task manager, stateful, and streaming servers
16 tools across 5 demo servers. All tools have descriptions (10-150 chars, mostly 50-100) and explicit input schemas with typed parameters. Naming follows verb_noun convention (add, subtract, read_file, create_note, etc.). However, parameter descriptions are minimal (5-40 chars), often just restating the parameter name. Output schemas are not documented, LLMs cannot infer what fields to expect from responses. Error handling is mentioned in some descriptions (divide by zero, total is zero) but no recovery guidance. No tool annotations (readOnlyHint, destructiveHint). Schemas are present but sparse, most parameters lack constraints (enums, min/max, patterns). This is a demo/test suite, not production code, which explains the gaps.
Add two numbers together
Create a new note with a title, content, and optional tags
Delete a file from the sandbox directory
Delete a note by ID
Divide the first number by the second. Returns an error if dividing by zero.
Get metadata (size, type, modification time) for a file or directory
Retrieve a note by its ID
Output schemas not documented. LLMs cannot infer response structure (fields, types, pagination). Forces agents to guess what data is available for downstream tool calls.
Parameter descriptions are minimal (5-40 chars), often just restating the name. Descriptions like 'First operand' and 'Number to subtract from' lack context on format, constraints, or valid ranges. LLMs cannot infer whether 'a' accepts floats, negative numbers, or has bounds.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | D | 59 | 2026-07-28+ | v2 |
List files and subdirectories in a sandbox directory
List all notes, optionally filtered by tag
Multiply two numbers together
Calculate what percentage 'value' is of 'total'. Returns an error if total is zero.
Raise a base number to an exponent (base^exp)
Read the text contents of a file from the sandbox directory
Subtract the second number from the first
Update a note's title, content, or tags (all fields optional)
Write text content to a file in the sandbox directory (creates or overwrites)
No tool annotations (readOnlyHint, destructiveHint, idempotentHint). Agents cannot distinguish safe reads from destructive writes without parsing descriptions. delete_file and delete_note should be marked destructive; read_file and get_note should be marked read-only.
No input validation constraints (enums, min/max, patterns). Parameters like 'path' in read_file lack format guidance. No indication of valid ranges for numeric parameters (divide exponent, percentage total). Agents may pass invalid values without early feedback.
Error handling lacks recovery guidance. divide and percentage mention error conditions (divide by zero, total is zero) but do not explain what the agent should do next. No actionable error messages or suggestions for retry/alternative paths.