This server provides tools for image search and other functionalities using the Model Context Protocol. Includes integration with Shutterstock API for image search capabilities.
This MCP server defines 5 tools with explicit schema registration via Zod, but suffers from critical gaps in parameter descriptions, missing output documentation, and several naming/composition issues. Only 1 of 5 tools has fully documented parameters. 3 tools have descriptions under 100 characters, leaving LLMs with insufficient context for tool selection. No tool documents its output structure, violating the pattern:tool-description and pattern:response-shaper patterns. The 'get_api_key' tool exposes sensitive environment data as a tool output, a critical security violation. Tool names are mostly descriptive but lack consistency: 'search_shutterstock' is specific, but 'greet' and 'echo' are utility stubs that do not align with the claimed primary purpose (Shutterstock image search). The composition violates pattern:tool by mixing unrelated concerns (echo, greet, calculate_area, API key retrieval, Shutterstock search) in a single server without clear domain separation. Error handling is minimal, the Shutterstock search function catches errors but returns unstructured strings rather than actionable recovery guidance (pattern:recovery-guide).
Calculate the area of a rectangle given its length and width.
Echo back the input text.
Retrieve the API key stored in the environment variable.
Greet a person with a customizable greeting. Both name and greeting are optional.
Search for images on Shutterstock. Specify the search term and optional image type and orientation.
Critical security vulnerability: get_api_key tool exposes API_KEY environment variable as a return value. Per pattern:secret-injection, credentials must never appear in tool responses or parameters, agent traces log all outputs, leaking secrets to logs and prompt history.
Output schemas are completely undocumented. No tool documents what fields are returned, what types they have, or how to use returned values in downstream calls. Per pattern:tool-description and pattern:response-shaper, agents need to know the structure of responses to plan multi-step operations.
Enum constraints are missing where critical. 'image_type' should be enum ['photo', 'vector', 'illustration']; 'orientation' should be enum ['horizontal', 'vertical']. Free-form strings invite hallucinated values ('oil painting', 'diagonal') that fail silently at the API layer.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 41 | - | v1 |
Numeric parameters lack bounds documentation. 'calculate_area' accepts 'length' and 'width' as z.number() with no validation of positive values or range limits. Per the rubric baseline, all numeric parameters should state 'min X to max Y' in the description.
Tool composition violates pattern:tool. Server mixes unrelated concerns: text echo, greetings, math, API key retrieval, and Shutterstock search. Each tool should do exactly one thing; these five tools span five domains with no clear relationship. The server should focus on image search or split into domain-specific servers.
Error handling returns unstructured strings rather than actionable recovery guidance. The searchShutterstock() function catches errors and returns plain text (e.g., 'Error searching for "term": <error.message>'). Per pattern:recovery-guide, errors must tell the LLM what to do next (retry vs. ask user vs. fatal).
Parameter descriptions lack consistency and completeness. 'greet' documents defaults only in the tool description ('defaults to World'), not in parameter annotations. 'search_shutterstock' uses inline examples ('e.g., photo, vector, illustration') instead of enum constraints. Per the rubric, every parameter must have a clear, standalone description.
Missing pagination support on search_shutterstock. The underlying API returns results paginated to 5 per page, but the tool does not expose page/limit parameters to the agent. Agents cannot fetch additional results or control result size. Per pattern:paginated-result, tools returning lists must support pagination.