Web search server using SerpApi with HTTP Streamable Transport
Server has 2 tools with adequate naming (verb_noun convention) and present descriptions. web_search has a reasonably detailed input schema with types and parameter descriptions; health_check lacks input documentation. Output schemas are not documented in the visible code, the web_search function returns a formatted string rather than structured JSON, which wastes tokens and forces LLM parsing. Error handling is minimal (basic try-catch with string error returns). Parameter descriptions are present but lack constraints (e.g., no enum for location format, no range validation hints for num_results). The server does not address idempotency, permission gates, or audit trails. Overall: competent naming and basic schemas, but missing structured output, error categorization, and composition patterns.
Health check endpoint for monitoring the MCP server
Search the web using SerpApi with support for localized results.
Output schema not documented; web_search returns formatted plaintext string instead of structured JSON. LLM must parse unstructured output, wastes tokens, risks extraction errors.
No output schema defined for either tool. Missing documented return types with field definitions prevents agents from planning downstream calls.
Error handling returns bare error strings ('ERROR: ...') without categorization (retryable, user-fixable, fatal) or recovery guidance. LLM cannot determine next action.
num_results parameter lacks explicit min/max constraints in schema. Code defaults invalid input to 10 silently; description claims 'max: 100' but schema does not enforce it.
Inferred effective spec: 2026-07-28+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 61 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 42 | - | v1 |
location parameter has no enum or format specification. Description gives examples ('New York, NY', 'London, UK') but does not specify what formats SerpApi actually accepts.
health_check has minimal description (16 chars) and no parameter or return documentation. Unclear what 'health' metric it checks or when to call it.
No audit trail, permission gates, or scope declarations. SERPAPI_API_KEY is injected server-side (good), but no logging of who called what with what parameters.
web_search always returns results as formatted string; no pagination support, no limit enforcement at output level. Large result sets could exceed token budgets.