Express-based backend service for a chatbot application with support for Gemini API, file uploads, YouTube search, speech-to-text transcription, chart generation, and flowchart visualization
This is not an MCP server. The codebase is a traditional Express.js REST API backend for a chatbot application (Luna) that exposes HTTP endpoints for chat, file uploads, user authentication, and generative AI features. While the repository claims to be a 'luna-chatbot-backend' and includes 29 tool-like endpoint handlers, these are NOT registered as MCP tools and do NOT conform to the MCP protocol. The 'tools' listed are inferred from Express route handlers and controller functions, there is no evidence of actual MCP tool registration, MCP transport, or MCP protocol implementation. No MCP server bootstrap code (ServerOptions, Tool interface, CallToolRequest handlers) is present. This fundamentally fails the MCP readiness criterion and should not be evaluated as an MCP server.
Transcribe audio files to text using OpenAI Whisper API
Create a feedback entry
Register a new user account
Delete a conversation and its messages
Execute a specific MCP resource/tool
Get API key health status for Gemini
Get a specific conversation with its messages
Retrieve all conversations for the authenticated user
No actual MCP tool registration, tools are inferred from Express route handlers and controller functions, not explicitly defined as MCP Tool objects with CallToolRequest handlers
Missing input/output schemas for 11+ tools (listResources, healthCheck, getConversations, getSuggestions, getUserStats, handleExcalidrawHealth, getAPIKeyStatus), schema must be visible in source code to be scored
Many tool names use generic, non-verb-first prefixes (handleGenerate, handleChatGenerate, handleUpload, executeResource) that fail the verb_noun convention; LLMs cannot disambiguate intent from names alone
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 29 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 30 | - | v1 |
Retrieve feedback entries with optional filters
Get conversation starters or follow-up suggestions
Retrieve user statistics including conversation counts and usage metrics
Authenticate user via Google OAuth
Generate Chart.js JSON configuration for data visualization
Generate chat response with conversation history support
Stream chat responses with real-time token output
Generate chat response and charts in parallel
Generate Excalidraw flowchart from text description using Groq
Health check endpoint for Excalidraw/Groq integration
Generate a text description of a flowchart for preview
Generate content using Gemini API with optional file uploads and search
Handle file uploads for documents and images
Health check endpoint for MCP services
List available MCP resources/tools
Authenticate user and return JWT token
Rename a conversation
Full-text search across message content
Update a message with Excalidraw diagram data
Update authenticated user profile
Search for videos on YouTube
Descriptions are generic and <60 characters for most tools (healthCheck, getUserStats, getSuggestions, handleExcalidrawHealth); descriptions under 20 chars score 0-20 ; most are 35-50 chars and lack LLM-optimized context (WHEN to use, WHAT it returns, WHY to call it)
No documented output/return schemas for any tool, LLMs cannot infer what fields to expect in responses, breaking downstream tool chaining and context inference
No error handling documentation or recovery guidance in tool descriptions, agents cannot determine if an error is retryable, user-fixable, or fatal
Credentials (GEMINI_API_KEY, SUPABASE_URL, OpenAI API keys) are passed as environment variables but NO documentation of secret injection patterns for agent tool use; agents may accidentally log or echo API keys from error responses
Parameter descriptions are missing or trivial for many parameters (e.g. 'Audio file' with no format constraints; 'Search query' with no length/format guidance); parameters named 'query', 'options', 'prompt', 'data' lack disambiguation
No pagination support documented for list tools (getConversations, getFeedback), responses could be unbounded, breaking context windows and agent reasoning
Tools mixing multiple concerns (handleChatWithChartsParallel generates both chat AND charts in one call; handleGenerate supports files AND search AND expert mode in one tool) violate single-responsibility principle; should be split so agents can compose them independently
Destructive operations (deleteConversation) lack confirmation/dry-run patterns, agents could accidentally delete conversations; no documented permission checks or audit trails