agentic platform for personalized career & education guidance
This server has 16 tools with moderate definition issues. Naming is generally clear and action-oriented (user_signup, user_signin, get_userdata, etc.), but many parameter descriptions are minimal or generic. The input schemas are present with basic types (string, integer, object) but lack enums for constrained fields (gender, stream, location_type, budget_range, reservation_category, mobility, language_preference). Parameter descriptions average 30-40 chars, below the 72-char baseline. The location parameter is typed as 'object' with no nested schema visible. Output schemas are completely undocumented; no tool describes what it returns or what fields the agent can expect. Error handling is absent, no guidance on retry logic, missing resources, or user-fixable failures. Security: user_signup and user_signin expose password as a string parameter with no validation rules visible. No permission checks, audit logging, or scope declarations are evident. Composition is reasonable (one action per tool), but chaining is at risk due to missing output documentation.
Create a new user profile with career guidance details
Fetch and analyze recommended colleges based on user profile and quiz results
Generate personalized career and stream recommendations based on quiz responses
Generate personalized academic and career roadmap timeline
Retrieve user profile by authenticated user
Retrieve stored timeline for authenticated user
No output/return schemas documented for any tool. LLMs cannot infer what fields to expect, breaking downstream tool chaining and forcing discovery detours.
Password exposed as plain string parameter in user_signup and user_signin. No validation rules, no requirement for HTTPS, no guidance on password format. Violates secret-injection pattern.
Multiple parameters accept free-form strings where enums should be used: gender (should be enum: male, female, other), stream (should enumerate stream options), budget_range, reservation_category, mobility, language_preference. LLMs will hallucinate invalid values.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 64 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 37 | - | v1 |
Retrieve user profile data by user ID
Health check endpoint to verify server is running
Refresh JWT access token using refresh token
Search colleges by field and location
Start a new personalized career guidance quiz
Submit answer to quiz question and get next question
Update user profile information
Sign out user and invalidate session
Sign in user with email and password
Create a new user account with email and password
location parameter typed as 'object' with no nested schema visible. LLMs cannot know what structure to pass (is it {state, city}? {lat, lng}? {address}?). Requires inline nested schema definition.
No error handling guidance. Tools lack recovery hints (e.g., 'If user not found, try search_users' or 'Quota exceeded; retry in 60 seconds'). Agents cannot disambiguate between retryable and fatal failures.
No permission gates or scope declarations. No indication which user roles can call sensitive tools like delete operations or update user profile. No audit trail or logging visible.
Many parameter descriptions are under 50 characters and lack context. E.g., 'User name' does not say max length, format, uniqueness constraints, or when to use this vs email for identification.
Destructive operations (user_logout) lack confirmation-request or dry-run pattern. An agent could accidentally log out a user mid-session.
class_level parameter accepts integer with no range specified. LLMs could pass 0, 100, or negative values. Description should state '9-12 (high school levels in India)'.
fetch_colleges and search_colleges both search colleges but with different signatures. LLMs may confuse when to use each. Consider merging or clarifying the distinction in descriptions.