A FastAPI-based chat application with MCP (Model Context Protocol) server integration for tool execution, supporting multiple AI providers (OpenAI, Anthropic, Google, Grok, OpenRouter) and image generation services.
DevoChat exposes a single tool 'visit_url' with a basic but incomplete definition. The tool has a verb-starting name and a reasonable description (120+ chars), but the schema is minimal, parameter descriptions lack detail, and there is no documented output schema. The tool lacks error handling guidance, security annotations, and clarity about what the response structure will be. With only one tool visible and significant gaps in schema documentation and error guidance, this falls squarely into the 'Fair to Poor' range.
Visits a URL, validates it for security (checks for localhost and private IPs), follows redirects, parses HTML content using BeautifulSoup, removes script/style tags, and returns cleaned text content.
No output schema documented. Tool description states it 'returns cleaned text content' but does not specify the structure of the response (string? object with fields?). LLMs cannot plan downstream calls or extract fields without knowing the output shape.
Parameter 'url' description lacks actionable constraints. States 'Max 20000 characters' but does not explain: what happens if URL exceeds limit? What format is required beyond 'HTTP or HTTPS'? Are query parameters allowed? Does it follow redirects (which the description mentions in the tool summary but not the param)?
No error handling guidance. Tool description mentions security validation (localhost/private IP checks) but does not document what happens if validation fails, what error message is returned, or what the LLM should do next (retry? ask user for a different URL?). This violates recovery-guide pattern.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 55 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 29 | - | v1 |
Tool makes external HTTP requests but no timeout, rate limit, or size constraint is documented. An LLM could pass a URL to a very large file or a slow server, hanging the tool indefinitely.
Security validation logic (localhost/private IP filtering) is mentioned in description but not formally specified. What IP ranges are blocked? What about IPv6 link-local addresses? Vague security descriptions invite bypasses.