Governed MCP server for Trino: every tool call carries the identity of the user the agent acts for, and the engine decides.
Strong foundation with well-named tools (verb_noun pattern), comprehensive descriptions (150-300 chars), and complete JSON Schema input definitions. All 6 tools have clear, governance-aware descriptions that explain data masking and access control. Parameters are typed and described. However, output schemas are documented only in descriptions, not as formal JSON Schema. Error handling lacks recovery guidance (no 'try X instead' patterns). Tool descriptions exceed the 10-1024 char guideline in some cases (describe_table is ~450 chars). Missing tool annotations (readOnlyHint, idempotentHint) despite all tools being read-only. No pagination support documented for list_* tools, risking context window overflow.
Describe a table: its columns, their types and comments, and optionally a few sample rows. Args: catalog, schema, table as bare names; sample_rows (0 to 20) adds that many rows of data. Returns JSON {"columns": [...], "rows": [...]} where each row is [name, type, extra, comment]; plus "table" (description, owner, tier, grain, joins, tags) and "column_context" (description, classification such as PII, known values) when the platform's catalogue knows the table; plus {"sample": {...}} when sample_rows > 0. Results are governed for the current user: values may come back masked (for example ***@domain) and rows or objects may be missing. That is the data access policy, not an error; report what is returned, verbatim, and do not retry the same call.
List the Trino catalogs (data sources) the current user can see. Returns a JSON array of catalog names. Start here, then list_schemas, list_tables and describe_table before writing SQL. Only catalogs the user is allowed to see are listed. Results are governed for the current user: values may come back masked (for example ***@domain) and rows or objects may be missing. That is the data access policy, not an error; report what is returned, verbatim, and do not retry the same call.
List the schemas of a catalog the current user can see. Args: catalog, a bare name from list_catalogs (no quotes, no dots). Returns a JSON array of schema names.
List the tables and views of a schema the current user can see. Args: catalog and schema, bare names (no quotes, no dots). Returns a JSON array of table names. Fully qualify them as catalog.schema.table in SQL.
Tool annotations missing: no readOnlyHint, idempotentHint, or destructiveHint declared despite all tools being read-only and idempotent. LLMs cannot infer safety properties without explicit annotations.
Output schemas documented only in prose descriptions, not as formal JSON Schema. LLMs cannot parse unstructured text to understand response structure for downstream tool chaining.
No pagination parameters (limit, offset, page_size) or result count limits documented for list_* tools. Large catalog/schema/table lists could exhaust context window.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 79 | 2026-07-28+ | v2 |
Run a read-only SQL query on Trino. Args: sql, a SELECT statement (no INSERT, UPDATE, DELETE, CREATE, DROP, ALTER, TRUNCATE, CALL, EXPLAIN, SHOW, DESCRIBE, USE, SET, RESET, or other non-query statement). The query runs under the current user's identity and is subject to Trino's access control and row-level security. Returns a JSON object {"columns": [...], "rows": [...]} where each row is an array of values. Results are governed for the current user: values may come back masked (for example ***@domain) and rows or objects may be missing. That is the data access policy, not an error; report what is returned, verbatim, and do not retry the same call.
Find tables that have a column whose name matches a pattern. Args: pattern, a SQL LIKE pattern on the column name, case-insensitive (use % as wildcard, e.g. "%email%"); catalog, optional bare name to search a single catalog (much faster). Without a catalog, every catalog the user can see is searched. Returns a JSON array of {"catalog", "schema", "table", "column", "type"}. Results are governed for the current user: values may come back masked (for example ***@domain) and rows or objects may be missing. That is the data access policy, not an error; report what is returned, verbatim, and do not retry the same call.
Error responses lack recovery guidance. Descriptions mention 'data access policy' but do not guide LLM on what to do if a resource is not found or masked.
describe_table description exceeds 450 chars, burying key details. Baseline for A+ tools is 50-200 chars. Trim to essential info and move examples to parameter descriptions.