A Model Context Protocol server that allows interaction with Twitter, enabling posting tweets and searching Twitter.
The Twitter MCP server has 2 tools with explicit JSON Schema definitions and descriptions. Tool names follow verb_noun convention (post_tweet, search_tweets), which is good. However, several critical definition gaps prevent a higher score: parameter descriptions are sparse (most params lack context-setting detail), no output schema is documented for either tool, and error handling lacks recovery guidance. The search_tweets tool accepts a numeric 'count' with constraints (min 10, max 100), which is sound, but post_tweet lacks validation guidance. Neither tool documents what fields the response will contain, forcing LLMs to guess about available fields for downstream chaining. Input validation occurs via Zod schemas (visible in types.ts reference) but the actual schema definitions are not visible in the provided source, so schema completeness cannot be fully verified.
Post a new tweet to Twitter
Search for tweets on Twitter
Output schemas not documented. Neither post_tweet nor search_tweets specifies what fields are returned. LLMs cannot plan downstream tool calls or extract required IDs (e.g., tweet_id, user_id) without this information.
Parameter descriptions lack depth. 'reply_to_tweet_id' is marked optional but no description states what happens if it's invalid (404, ignored, error). 'query' in search_tweets has no guidance on format (hashtags, @mentions, quoted strings, operators). Descriptions should answer WHAT the param does and WHEN/HOW to use it.
Error handling lacks recovery guidance. The code catches TwitterError and McpError but returns generic messages like 'Rate limit exceeded. Please wait a moment before trying again.' without actionable next steps. No distinction between retryable, user-fixable, and fatal errors.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 41 | - | v1 |
No pagination or result limit enforcement for search_tweets. While 'count' is bounded (10-100), the tool does not document whether it returns all matching tweets or applies any additional filtering. A description like 'Returns up to [count] most recent tweets matching the query' would clarify expected behavior.
API credentials exposed in Dockerfile. The Dockerfile sets environment variables (API_KEY, API_SECRET_KEY, ACCESS_TOKEN, ACCESS_TOKEN_SECRET) with placeholder values. While the source code (index.ts) correctly uses dotenv and does not expose secrets as tool parameters, the Dockerfile as an artifact is a deployment security risk, credentials should never appear in version-controlled files.