An xmcp application with tool syntax for Meta/Facebook Ads API integration
Scoring was not performed
CRITICAL: No tool definitions visible in provided source code. All 44 tools are inferred from test scripts and file structure, not directly inspectable. Cannot verify schemas, descriptions, or parameter documentation exist.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 22 | 2025-06-18+ | v2 |
| 2026-03-09 | F | 17 | v23.0+ | v1 |
CRITICAL: OAuth tokens and API secrets (META_ACCESS_TOKEN, META_APP_SECRET) are exposed in environment variables in test scripts. No evidence of server-side secret injection pattern in actual tool implementation.
HIGH: No parameter descriptions visible for any tool. LLMs cannot infer parameter semantics from names alone (e.g., does 'status' mean HTTP status, campaign status, or a boolean flag?).
HIGH: Destructive operations (delete_campaign, delete_adset, delete_audience, delete_creative) lack confirmation or dry-run patterns. No evidence of guarding against accidental deletions.
HIGH: No input schema validation visible. Tools accept parameters but schema definitions (type, required, enum, format) are not present in sample code.
MEDIUM: Large list tools (list_campaigns, list_adsets, list_audiences, list_creatives) lack explicit pagination documentation. No evidence of limit/offset parameters, cursors, or result count caps.
MEDIUM: No error handling guidance visible. Tools should return actionable error messages (e.g., 'Campaign not found. Try list_campaigns() to see available IDs') instead of raw API errors.
MEDIUM: No tool descriptions visible to justify when to use create_image_creative vs create_video_creative vs create_carousel_creative. LLMs cannot distinguish between similar tools.