Flexible, pluggable tracing middleware for Model Context Protocol (MCP) servers in JavaScript/TypeScript
This is a tracing/middleware library, not a production MCP server with complete tool definitions. Both tools ('add' and 'createUser') are defined in example/streamable-http-server.ts with Zod schemas, but parameter descriptions are entirely missing (null values in Input schema). Tool descriptions exist but are minimal (9-12 words). The library itself provides tracing infrastructure, not well-defined tool interfaces. Per the hard rules: parameters lack descriptions → schema score capped at 30 max per tool. Missing param descriptions is a critical gap that prevents LLMs from understanding what each parameter controls.
Adds two numbers.
Creates a user with personal information (PII will be redacted in traces).
All input parameters lack descriptions (null values). Parameters 'a', 'b', 'name', 'email', 'password', 'phone', 'ssn' have no guidance text for LLM interpretation.
Tool descriptions are too brief (9-12 words). 'Adds two numbers.' and 'Creates a user with personal information (PII will be redacted in traces).' lack context on WHEN to use, prerequisites, or what the output contains.
The 'createUser' tool accepts a plain-text 'password' parameter. No indication of hashing, minimum length, or security handling. Violates secret-injection pattern by exposing credentials as tool input.
No output schema documentation. Neither tool documents what fields/structure the response contains. For 'add', is the result a number or an object? For 'createUser', what user fields are returned?
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 47 | <=2025-11-25 | v2 |
| 2026-03-09 | D | 50 | - | v1 |
No error handling guidance. Tools do not document failure modes, retry behavior, or how LLMs should respond to errors (e.g., invalid email format, password too weak, duplicate user).
Parameter naming inconsistency: 'createUser' uses 'ssn' but the redaction function also looks for 'socialSecurityNumber'. LLM may not know which field name is correct.