MCP server for Xiayan, a Python-based Markdown formatting tool for WeChat Official Account publishing
This MCP server has 7 tools with moderate definition quality. Most tools have descriptions (ranging from 84-180 chars), but lack critical elements like error handling guidance, parameter validation rules, and output schema documentation. Input schemas are present and properly formatted with JSON Schema, but descriptions are minimal and don't adequately explain when to use each tool or what to do if it fails. The server uses STDIO transport only, which caps protocol readiness severely. No tool annotations (readOnlyHint, destructiveHint, idempotentHint) are present despite clear semantics (e.g., publish_article and remove_theme are destructive). Parameter descriptions are terse and often lack constraint details. Error classification, recovery guidance, and confirmation patterns for irreversible operations are absent.
Add a custom theme to the theme manager.
Get current WeChat API credentials (returns masked App Secret for security).
List the themes compatible with the 'publish_article' tool to publish an article to '微信公众号'.
Get HTML preview of a theme with sample content.
Format a Markdown article using a selected theme and publish it to '微信公众号'.
Remove a custom theme from the theme manager.
Update WeChat API credentials (App ID and App Secret).
No tool annotations (destructiveHint, readOnlyHint, idempotentHint) declared despite clear semantics. remove_theme should be marked as destructive; publish_article should be marked as WRITE. This prevents agents from safely reasoning about side effects.
Missing error handling and recovery guidance. No tool describes what to do on failure (e.g., if WeChat API call fails, if theme_id is invalid, if credentials are missing). Agents have no recovery path.
No output schema documentation. Tools return results but the schema of the return value is not documented. Agents cannot plan downstream calls or extract fields reliably.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 34 | - | v1 |
Irreversible operations (remove_theme, publish_article, update_wechat_credentials) lack confirmation/dry-run patterns. Agents can destroy data without safeguards.
Parameter descriptions are minimal and lack constraint details. E.g., 'theme_id' description should specify valid format/examples (default, orangeheart, rainbow, lapis, pie, maize, purple, phycat are listed in publish_article but not as enum in list_themes). 'permanent_cover' bool lacks context on when to use true vs false.
update_wechat_credentials and get_wechat_credentials expose credential management as tools, but descriptions don't clarify permissions, scope, or audit trail. No indication that this is a security-sensitive operation or who can call it.
remove_theme description (45 chars) is too short: 'Remove a custom theme from the theme manager.' Does not explain when to use it, what happens to articles using that theme, or if it's irreversible.
publish_article description mentions 'preserving its frontmatter (if present)' but no parameter describes frontmatter format or parsing behavior. Agents cannot tell if frontmatter is required, optional, or parsed automatically.