OWASP harness for executable security regression testing of agentic applications and MCP-integrated systems.
Two tools with minimal documentation. read_file has a basic description (54 chars) and a single string parameter with minimal context. delete_file has identical description length but no visible input schema in the provided code excerpt. Both tools lack comprehensive parameter descriptions, output schema documentation, and error handling guidance. The server appears to be a test harness fixture, not a production MCP server, which explains the sparse definitions. No tool annotations (readOnlyHint/destructiveHint) despite clear risk profiles.
Delete one regular file from the fixture root.
Read a UTF-8 text file from the fixture root.
Tool descriptions are 54 characters, below the 10 - 1024 character baseline and lack context on WHEN to use each tool or WHAT it returns. Descriptions should explain prerequisites, return structure, and error cases.
No output schema documented for either tool. LLMs cannot plan downstream calls or extract return values without knowing the response structure.
delete_file is marked DESTRUCTIVE but has no tool annotation (destructiveHint) and no confirmation/dry-run pattern. Agents should be warned before irreversible operations.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | F | 49 | 2026-07-28+ | v2 |
Parameter descriptions are minimal ('Relative path to the file within the fixture root'). Should include format constraints, length limits, and examples of valid paths.