MCP server for TypeScript learning assistance with deep web search and documentation lookup capabilities
TySVA provides 2 tools with explicit descriptions and basic parameter schemas, but critical gaps in parameter documentation, output schema definition, and error handling significantly undermine production readiness. Tool names follow verb_noun convention, but descriptions lack LLM-optimization details (query format, expected return structure, when to use each vs. the other). Input schemas exist but parameter descriptions are minimal ('The search query for...' is generic and non-actionable). No output schemas documented, agents cannot plan downstream operations or understand what fields to extract. Error handling is entirely absent, no guidance on retries, fallbacks, or failure modes. The server integrates sophisticated backends (Qdrant, HyDE, Linkup API) but does not expose this architecture through clear tool contracts.
Useful to search for precise information in the depths of the web when you need to answer advanced and/or complicated questions by the user about Typescript (especially debugging and errors).
Useful to search for specific information within a database containing TypeScript documentation.
Parameter descriptions are generic and non-actionable. Both tools accept a 'query' parameter described only as 'The search query for [deep web|TypeScript documentation]', no guidance on format, length constraints, expected syntax, or examples of good queries.
No output schema documented. Tool descriptions state what is returned (answer, sources, markdown response) but LLMs have no structured definition of return fields, types, or chaining references. Agents cannot plan downstream operations or extract values reliably.
No error handling or recovery guidance. Code does not catch exceptions from LinkupClient.search() or hyde_qe.aquery(), does not validate query input (length, encoding, SQL injection risk), and does not return actionable error messages. Agents hitting failures receive unstructured exceptions.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 37 | - | v1 |
Tool disambiguation missing. Both tools are search functions but serve different domains (web vs. local TypeScript docs). Descriptions do not explain when to use deepsearch_tool instead of documentation_search_tool, LLMs must guess.
No input validation. Query parameter has no length bounds, no format constraints, and no validation against command injection or path traversal. Agents can pass arbitrary strings without constraint.
API keys hardcoded into Docker secret files without per-request rotation or rate limiting. LinkupClient and Groq credentials are read at startup, not passed via environment per-request.