MCP server for Douyin video upload automation
This server has 5 tools with adequate but not production-grade definitions. Tool names follow verb_noun convention (good), but descriptions are minimal (10 - 40 chars, well below the 50 - 200 char optimum for LLMs). Input schemas are present and properly typed using Zod validation, but output schemas are undocumented in the tool definitions. Error handling is generic ('❌ Login failed: ${result.error}') with no recovery guidance. No tool has parameter constraints (enums), and all tools accept free-form string inputs vulnerable to injection. The server lacks output schema documentation, pagination for list operations, and structured error categorization. Security is a major concern: login credentials and browser state are managed client-side via Puppeteer with no clear secret injection pattern. Most tools would score 40 - 60 individually; the average lands at fair/poor (C grade).
Check if saved cookies are valid and can auto-login
Clear saved cookies and browser data
Get saved cookies information
Login to Douyin Creator Platform and save cookies. Opens browser for manual login.
Upload a video to Douyin with specified title and description
Tool descriptions are extremely brief (10 - 40 characters), far below the 50 - 200 character optimum for LLM tool selection. E.g., 'Get saved cookies information' provides no context on when to use this tool or what data structure is returned. LLMs cannot confidently select between similar tools without richer descriptions.
No input schema documentation or output schema documentation. Tool definitions declare input parameters but do not describe the structure or data type of responses. Without documented response schemas, LLMs cannot plan downstream tool calls or extract expected fields. Example: douyin_login returns 'success', 'user', 'cookieCount', 'error', but this is never declared in the tool definition.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 36 | - | v1 |
Error messages lack actionable recovery guidance. Example: 'Login failed' does not tell the LLM whether to retry, ask the user for help, or escalate. Per pattern:recovery-guide, errors should categorize as retryable, user-fixable, or fatal and suggest next steps.
No parameter validation or constraints beyond type. All string parameters (videoPath, title, description, tags) are free-form with no format, length, or character restrictions documented. LLMs can pass arbitrary input without guidance on valid values. Example: videoPath should document valid file extensions and whether paths are absolute or relative.
Credentials and session state managed in plaintext files without explicit secret injection pattern. Douyin login credentials and browser cookies are stored locally via Puppeteer without evidence of environment variable or vault-based secret management. Agent traces log parameters and could expose sensitive session data.
Destructive operations (douyin_clear_cookies) have no confirmation step, dry-run option, or reversible guarantee. An agent could accidentally wipe all saved cookies without user approval. Pattern:confirmation-request recommends requiring explicit confirmation for irreversible operations.
No permission gates or scope declarations. Tools like douyin_clear_cookies and douyin_upload_video have no access control to verify the calling agent/user is authorized. This could allow unauthorized video uploads or data destruction. Per pattern:permission-gate, destructive tools should gate behind permission checks.
Tool composition combines multiple concerns. douyin_login is both a browser interaction and a state-saving operation. This makes it difficult for agents to reason about partial failures (e.g., successful login but cookie save failed). Per pattern:tool, each tool should do exactly one thing.