MCP server for Node-RED — safe deploy with optimistic locking, smart search, full flow management via AI assistants
nr-mcp demonstrates solid naming conventions (verb_noun pattern: nr_get_*, nr_search_*, nr_create_*, nr_delete_*, nr_inject_*, nr_install_*) and comprehensive parameter schemas with type definitions. Tool descriptions are present and contextual (avg ~120 chars), exceeding the 20-char minimum. However, parameter descriptions are inconsistent, some parameters lack detail on constraints, formats, or valid ranges. Output schemas are not formally documented in the code; responses are inferred from implementation. Error handling exists but lacks recovery guidance (e.g., nr_search_nodes returns truncated results without suggesting pagination). No tool annotations (readOnlyHint/destructiveHint) despite clear risk levels. Composition is strong: tools chain well (search → get → deploy), and responses include necessary IDs for downstream calls.
Create one or more new nodes/groups in a single deploy. Each node dict must include 'id', 'type', and 'z' (target tab ID). Groups need 'type': 'group'. Config nodes (e.g. ha-entity-config) use 'z': '' for global scope.
Delete one or more nodes by ID. Also cleans up references: removes deleted IDs from group.nodes arrays and from other nodes' wires arrays.
Read debug output from flow context. Use when a flow has a catch node that stores errors/debug data to flow context. Pass key=null to list all context keys. Trigger flow with nr_inject first, then read this.
Get a single Node-RED tab with all its nodes and groups. Accepts tab name (case-insensitive) or tab ID.
Read Node-RED flow context variables. Pass key=null to list all keys, or a specific key to get its value.
No tool annotations (readOnlyHint/destructiveHint/idempotentHint) despite clear risk levels declared in metadata. nr_delete_nodes (DESTRUCTIVE), nr_safe_deploy (WRITE), nr_inject (WRITE), nr_install_module (WRITE) should carry explicit annotations to guide agent behavior.
Parameter descriptions lack constraint details. 'max_results' in nr_search_nodes has no range (default 20, but min/max unknown). 'fields' in nr_safe_deploy says 'cannot modify id, type, z' but no schema for allowed field names. 'nodes' in nr_create_nodes requires 'id, type, z' but no validation rules documented.
Output schemas not formally documented. Responses are inferred from implementation (e.g., nr_get_flow returns {tab, nodes, groups, total_nodes}). LLMs cannot plan downstream calls without explicit schema documentation. No return type hints in tool docstrings.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 72 | 2026-07-28+ | v2 |
Quick overview of all Node-RED tabs with node counts and groups.
Extract full JavaScript code from a Node-RED function node.
List installed Node-RED modules and their node types. Optionally filter by module name or node type containing `query` string. Returns module name, version, and list of node types provided.
Get full node configuration including wires, upstream/downstream connections, and group membership.
Trigger an inject node to fire immediately. Use nr_search_nodes to find inject nodes first. The node must be of type 'inject'.
Install a new Node-RED module (npm package) from the registry. Use nr_get_installed_modules to check what's already installed first. Installation may take 30-60 seconds.
Deploy changes to a Node-RED node with optimistic locking. Uses correct GET→POST pattern (never PUT). Preserves tab order.
Search Node-RED nodes by name, type, or function code content. Searches in: name, type, func, template, action fields.
Error handling lacks recovery guidance. nr_search_nodes returns truncated results silently (truncated: true) without suggesting pagination or retry strategy. nr_get_flow raises NRNotFoundError for ambiguous tab names but does not suggest alternatives. No actionable error messages for LLM self-correction.
Destructive operations (nr_delete_nodes, nr_install_module) lack confirmation/dry-run support. Agents can delete multiple nodes or install untested modules without a safety gate. No idempotency guarantees documented for retry scenarios.