Simple MCP weather server using Open-Meteo API
The Weather MCP server has 5 tools with clear naming conventions (all verb_noun pattern: get_*, add_*, delete_*). Descriptions are present and reasonably detailed (80-120 chars). Input schemas are well-formed with proper JSON Schema structure, including enums where appropriate (unit parameter). However, there are notable gaps: no output schemas documented, error handling lacks actionable recovery guidance, and some tool descriptions could be more prescriptive about when to use them vs alternatives. Security considerations are partially addressed (OAuth setup visible) but no per-tool permission declarations. Tool composition is sound, each tool has a single responsibility, though the pair (delete_location / delete_all_locations) could benefit from confirmation patterns.
Save a location with a custom label for quick access
Delete all saved locations for the authenticated user
Delete a saved location by its label
Get the current weather for a location
Get all saved locations for the authenticated user
Output schemas not documented. LLMs cannot plan downstream calls or extract required fields (e.g., after get_locations, what fields are returned?). No pagination info for list operations.
Destructive operations (delete_location, delete_all_locations) lack confirmation or dry-run support. An agent could accidentally delete all saved locations without user approval.
Error responses visible in code use generic messages (e.g., 'Location not found') without actionable recovery guidance. Should suggest: 'Try get_locations() to see available saved locations' or 'Verify spelling and try again'.
delete_all_locations has a minimal description (50 chars) that does not warn of consequences or recommend caution. Destructive operations should explicitly state irreversibility.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 0 | - | v1 |
No tool-level permission declarations (e.g., 'requires: read:locations', 'requires: write:locations'). Cannot audit least-privilege agent configurations.
get_current_weather description does not mention that location can be either a city name OR a saved label. This creates ambiguity and may cause LLM to try unsupported formats.