MCP server providing file operations (read, write, list) and code analysis capabilities via HTTP transport with workspace directory isolation
Four tools with basic schemas and descriptions, but significant gaps in parameter documentation, output schema clarity, and error handling guidance. read_file, write_file, and list_files have minimal descriptions (20-50 chars) and lack detail on return formats. analyze_code's description is verbose but educational rather than production-focused, and references deprecated sampling pattern. No tool declares output schema structure. Error messages are generic strings rather than structured responses. Parameter descriptions exist but are minimal. No tool annotations (readOnlyHint, destructiveHint) despite clear risk profiles.
Analyze code focusing on specified aspect. In a full MCP implementation with bidirectional communication, this tool would send a sampling/createMessage JSON-RPC request to the client. For this educational lab, we return a message indicating where sampling would occur.
List files in a directory within the workspace.
Read a file from the workspace directory.
Write content to a file in the workspace directory.
Tool descriptions are too brief (20-50 chars) and lack context for LLM selection. 'Read a file from the workspace directory' does not explain when to use this vs other tools, what format is returned, or error recovery steps.
No output schema documented. Tools return plain strings; LLMs cannot parse structured results or extract IDs for chaining. list_files returns 'DIR: path (bytes)' format but this is undocumented.
Error responses are unstructured strings ('Error: Access denied...') without recovery guidance. LLMs cannot determine if errors are retryable, user-fixable, or fatal.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | F | 49 | <=2025-11-25 | v2 |
analyze_code references deprecated sampling/createMessage pattern and acknowledges it requires 'low-level MCP SDK'. This pattern was removed from the spec; tool should integrate directly with LLM provider or be redesigned.
write_file lacks confirmation or dry-run capability for an irreversible operation. Agents can accidentally overwrite files without safeguards.