MCP server for managing Japanese language study progress, lessons, and payment history with Supabase integration
This server has significant quality gaps across naming, descriptions, schemas, and error handling. While tool names are verb-based, many parameters lack proper type annotations and descriptions. Several tools return unstructured JSON strings instead of typed objects. Error handling is minimal, most failures return generic exception messages with no recovery guidance. The server exposes Supabase schema details (table names, field names) directly in tool descriptions, creating a security concern. No input validation, no idempotency guidance, no pagination documentation. Per-tool analysis reveals 4 tools with incomplete schemas and 2 tools with minimal descriptions.
학습기록 생성 - 새로운 학습 진도 데이터를 저장합니다.
액티비티 목록 조회 - douki_activities 테이블에서 액티비티를 검색합니다.
특정 레슨의 단어와 문법을 한 번에 가져옵니다.
특정 레슨의 일본어 문법을 가져옵니다.
특정 레슨의 일본어 단어를 가져옵니다.
결제 내역 목록 조회 - douki_payment_history 테이블에서 결제 기록을 검색합니다.
학습기록 전체 조회 - 저장된 학습 진도 데이터를 최신순으로 반환합니다. 반환되는 각 레코드의 senderKey와 roomTag는 없을 수도 있는 nullable 필드. senderName 이 '코토하' 일 경우 선생님이 말한 경우라고 생각해줘.
No input schemas visible in source code. All tools return raw JSON strings instead of typed objects. The MCP protocol requires input/output schemas; FastMCP should generate these automatically, but the code does not show explicit schema definitions.
Parameters lack descriptions in source. 'lesson_number' in get_lesson_vocab has a description, but many optional parameters (user_id, status, from_date, to_date in get_payment_history) have descriptions only in the tool docstring, not visible as structured parameter metadata.
Error handling returns generic exception messages (e.g., 'Exception: ...' caught and returned as-is). No recovery guidance, no categorization (retryable vs fatal), no actionable next steps for the LLM.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 44 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 29 | - | v1 |
All tools return all available fields from Supabase (e.g., response.data dumped as-is in get_payment_history, get_activities). No field filtering, no pagination limit enforcement (default 50 is set but not enforced for large datasets), no documentation of what fields are returned.
create_study_record requires 'data' as a JSON string parameter. No validation of the JSON structure, no enum constraints on optional fields (senderName, senderKey, roomTag). Accepts arbitrary JSON, risking malformed data storage.
Tool descriptions mention internal details: 'douki_payment_history table', 'douki_activities table', Supabase field names. This exposes schema structure and database implementation, a security concern. Descriptions should be user-focused, not implementation-focused.
No idempotency guidance. create_study_record has no idempotent key; retrying the same call will create duplicate records. No dry-run or confirmation step for write operations.
Parameters use 'Optional[str]' in Python, but no description of the expected format for date parameters (from_date, to_date). The docstring mentions ISO 8601, but parameter metadata does not include format constraints or examples.
get_lesson_vocab, get_lesson_grammar, get_lesson_content return unstructured error responses with 'error' field in place of 'contents'. This breaks the contract with tools expecting a 'contents' key. No clear error structure or recovery path.