ClineMCP has 7 tools with complete input schemas and descriptions, but quality is inconsistent. Tool names follow verb_noun convention (cline_start, cline_status, cline_cancel, cline_output, cline_tail, ensure_clinerules). Descriptions are present but brief (avg ~60 chars, below the 194-char baseline). Parameters have types and descriptions, but lack constraints (enums, ranges, patterns). Output schemas are not documented, responses are JSON strings without declared structure. Error handling is minimal; most tools return JSON with error fields but lack recovery guidance. Security concern: session_id is passed as a parameter rather than extracted from request context, and no permission checks are visible. The tool composition is reasonable (single responsibility), but parameter naming could be more explicit (e.g., 'lines' should specify range 1-1000).
Kill active subprocess
Mark complete, send Telegram
Return full session output
Spawn Cline session, return session_id
Return current status, elapsed time, output preview
Return the last N lines of a running or completed session's output
Check for .clinerules in a repo and generate one if missing. If agent_type is provided, merges per-type template with existing repo rules. Template content comes first, repo rules append below --- separator.
Output schemas not documented. Tools return JSON strings without declared field types or structure. LLMs cannot plan downstream calls or extract fields reliably.
Parameter constraints missing. 'lines' parameter in cline_tail has no min/max bounds; 'step_id' in cline_complete has no type validation; 'status' values are not enumerated.
Error handling lacks recovery guidance. Errors return JSON with 'error' field but do not suggest next steps (e.g., 'Session not found. Call cline_start() to create one.').
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 69 | <=2025-11-25 | v2 |
Descriptions are too brief (avg 60 chars vs 194-char baseline). 'Kill active subprocess' and 'Return full session output' lack context on when to use each tool and what they return.
No permission checks visible. Tools accept session_id as a parameter without verifying caller authorization. A malicious agent could cancel or inspect any session.