A secure MCP server for Evernote integration with OAuth 1.0a authentication and automatic token expiration handling
The server has 4 well-named tools with complete input schemas and consistent descriptions. Tool names follow verb_noun convention (createSearch, getSearch, getNote, getNoteContent), which is excellent for LLM comprehension. All tools are read-only, which is appropriate. However, output schemas are completely undocumented, there is no specification of what fields these tools return, making it difficult for LLMs to plan downstream operations or extract required data for chaining. Parameter descriptions are present and reasonably detailed (e.g., maxResults with min/max bounds, format with enum choices), but some lack actionable context (e.g., 'Natural language search query' without guidance on what patterns work best). Error handling is not visible in the provided code, no error recovery guidance, no categorization of retryable vs user-fixable failures. Tool composition is good: each tool has a single responsibility. Security appears sound (read-only operations, no credential parameters visible), but logging/audit patterns are not evident.
Search for notes in Evernote using natural language queries
Retrieve metadata and basic information for a specific note by its GUID
Retrieve the full content of a specific note in a readable format
Get details about a previously executed search by its ID
Output schemas completely undocumented. No specification of return types, field names, or structure for any of the 4 tools. LLMs cannot plan downstream operations (e.g., what field contains the note GUID after createSearch returns?), forcing exploratory calls and context loss.
No error recovery guidance visible. The code does not show how errors are classified or what recovery steps LLMs should take (retry, ask user, abort). Raw error codes or stack traces will not help agents self-correct.
Parameter descriptions lack actionable context for getSearch and getNote. 'Unique identifier of the search' and 'The unique identifier (GUID)' do not explain format, how to obtain these IDs, or what to do if they are invalid.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 68 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 59 | 2025-06-18+ | v1 |
Result limits not enforced or documented for createSearch. The maxResults parameter caps at 100, but the tool description does not explain what happens if that returns 100 items, whether pagination is required, or how to fetch the next page.