ChocoDrop: real-time AI image drops for 3D scenes via Model Context Protocol (MCP). Places local images, videos, and GLB files into a ChocoDrop browser scene.
ChocoDrop MCP server defines 2 tools with reasonable structure but inconsistent quality. Tool naming follows verb_noun convention (get_status, import_asset), which is correct. Both tools have descriptions, though they are brief (39-90 chars vs baseline 194). Input schemas are present and properly typed for both tools. However, parameter descriptions are sparse and output schemas are not documented. The import_asset tool has well-structured positional parameters with type constraints (x, y, z as required numbers), but lacks guidance on valid file formats beyond the description. Error handling and recovery paths are not evident in the provided code. Security-wise, the tools appear to operate on local file paths, but no validation against path traversal or injection is visible in the source excerpt.
Get the local ChocoDrop scene URL and connection state.
Import one allowed local asset into the connected ChocoDrop browser scene.
Minimal tool descriptions lack LLM-optimized guidance. get_status (39 chars) and import_asset (90 chars) are below baseline (194 chars avg) and do not explain WHEN to use or WHAT happens next.
No documented output schemas. LLMs cannot infer what fields get_status returns (e.g., is it {url, state} or {sceneUrl, connectionStatus}?) or what import_asset returns on success/failure.
Parameter descriptions are missing or minimal. 'path' in import_asset says 'File path to the local asset' but does not clarify allowed extensions, max file size, or path traversal constraints.
No error handling guidance. What happens if the asset file does not exist? If WebSocket connection to scene is lost? If position coordinates are out of bounds? Error responses should guide recovery (retry, try different approach, etc.).
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 29 | - | v1 |
No input validation constraints visible. import_asset accepts 'path' with minLength:1 but no pattern/maxLength to prevent path traversal (../../../etc/passwd). No enum or pattern for position bounds.
Tool annotations (readOnlyHint, destructiveHint, idempotentHint) are absent. get_status is marked Risk:READ_ONLY and import_asset Risk:WRITE in the metadata, but these are not reflected in tool schema annotations per current MCP spec.