Healthcare MCP Server for medical information access
The Healthcare MCP server presents 9 tools with mixed quality. All tools have descriptions (10-50 chars), but they are uniformly brief and lack actionable detail for LLM selection. Input schemas are present and structured, but parameter descriptions are minimal. No output schemas are documented. Error handling exists at the implementation level (base-tool.js shows formatErrorResponse), but tools do not guide recovery or classify errors as retryable/fatal. The codebase is well-organized with a BaseTool abstraction and caching, but lacks domain-specific patterns from the 54 Agentic Tool Patterns, no composition hints, no pagination guidance, no permission gates despite medical data sensitivity, and no confirmation steps for irreversible operations (though all 9 tools are READ_ONLY, which is correct). Parameter names are generally clear (fda_drug_lookup, pubmed_search, clinical_trials_search), but descriptions are too sparse to guide an LLM toward correct usage. No tool combines related operations (e.g., all search/lookup tools are separate, which is good), and composition is simple. Critical gaps: no output schema documentation, no recovery guidance in error messages, minimal parameter descriptions, and no security/audit logging despite healthcare domain sensitivity.
Calculate Body Mass Index (BMI)
Search for clinical trials by condition, status, and other parameters
Extract metadata from a DICOM file
Look up drug information from the FDA database
Get evidence-based health information on various topics
Look up ICD-10 codes by code or description
Search for pre-print articles on medRxiv
Search the NCBI Bookshelf
Output schemas are not documented. Tools return data but LLMs cannot see what fields to expect, forcing them to guess at downstream parameter mappings and increasing errors.
Tool descriptions are too brief (30-50 chars). They do not answer WHEN to use the tool, WHAT it returns, or prerequisites. Current descriptions lack actionable detail.
Parameter descriptions are minimal or missing context. E.g., 'search_type' in fda_drug_lookup lists enum values but does not explain when to use 'label' vs 'adverse_events'. LLMs need dependency hints to make smart choices.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 35 | - | v1 |
Search for medical literature in PubMed database
No error recovery guidance. Base tool formats errors as {status: 'error', error_message: ...} but does not classify errors as retryable, user-fixable, or fatal. Agents cannot know whether to retry, ask the user, or abort.
Healthcare domain is sensitive yet no audit logging, permission gates, or access controls are visible. Tools can be called by any agent without scope verification. No user/context tracking in tool invocations.
Pagination is mentioned in clinical_trials_search (maxResults, max: 100) and other search tools, but no pagination parameters (page, offset, cursor) or next_cursor guidance in responses are documented. Agents cannot paginate through large result sets.
extract_dicom_metadata accepts a file_path parameter but does not document security implications of file system access. No validation against path traversal or check for sandboxing constraints.
calculate_bmi does not document units or precision expectations. Is height_meters a float like 1.75, or is it an integer cm? Does output BMI round to 1 or 2 decimals? LLMs will guess.