A medical education assistant server that scrapes medical information, textbook prices, quiz questions, and study resources. Provides authentication, Google Sheets integration, email notifications, and AI-powered scheduling for medical students and doctors.
The Meducate MCP server has 21 tools with generally reasonable descriptions (100-300 chars), but exhibits critical deficiencies in schema completeness, parameter documentation, and error handling patterns. Tools are mostly well-named with action verbs (scrape_*, list_*, query_*, get_*), but parameter schemas are severely under-documented. Only ~60% of parameters have explicit descriptions. Output schemas are largely absent or unspecified. Error handling is minimal, tools catch exceptions and return generic error messages without actionable recovery guidance. The server returns string/dict responses without structured field documentation, making it difficult for LLMs to chain tools or extract specific fields. No tool demonstrates the constrained-input pattern (enums), no tool includes per-item success/failure for batch operations, and no tool surfaces the IDs needed for downstream chaining. The authentication tools (google_authenticate, complete_browser_auth) lack parameter validation logic and return demo/placeholder user objects. Medical scraping tools (scrape_disease, scrape_book_prices) depend on external Puppeteer APIs and lack documented rate limiting, timeout handling, or partial failure recovery. Overall: definitions exist and are readable, but lack the rigor required for reliable agent operation.
Log out the currently authenticated user.
Return current authentication status and user info if logged in.
Complete the browser-based OAuth flow with a one-time code. In this demo implementation, `code` is matched against our pending codes. In a real deployment, you'd fetch the user session associated with this code from your backend and call set_authenticated_user().
Get citation references for a specific disease from scraped sources.
Authenticate using a Google ID token obtained from Google Sign-In.
List all diseases available in the scraped database.
Critical: Output schemas not documented. Tools return unstructured strings or dicts without specifying expected fields, types, or structure. LLMs cannot reliably extract specific fields for downstream chaining. Pattern 'response-shaper' calls for documented return types; 100% of A+ tools provide them.
High: Parameters lack descriptions and type constraints. scrape_book_prices 'sources' param and scrape_disease 'sources' param are not self-documenting; 'difficulty' param in scrape_quiz_questions has no enum definition, inviting hallucinated values. Pattern 'constrained-input' requires enums for fixed option sets.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 48 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 36 | - | v1 |
List all previously scraped medical book price data.
List all previously scraped quiz question sets.
List all previously scraped study resource collections.
Query previously scraped disease information from local database.
Fetches data from a Google Sheet. No arguments required, it returns all the data.
Scrape medical textbook prices from online sources.
Scrape information about the 20 most common diseases in Africa. This is useful for building a comprehensive medical education database.
Scrape medical information about a specific disease from trusted sources. Anytime a user asks about eliciting a disease, call this tool.
Scrape medical information for multiple diseases at once.
Scrape medical MCQ quiz questions for a specific topic.
Scrape medical study resources including videos and articles.
Search through all scraped medical content for specific information.
Sends a gmail notification to a user, can be used as a personal reminder also
Start a browser-based OAuth flow and return a URL to open. Returns a dict with a url and a state code. The user should open the URL, complete sign-in, and the browser callback page will display a one-time code. Then call `complete_browser_auth(code)` here to finish.
Appends data to a Google Sheet.
High: Error handling does not guide recovery. Tools catch exceptions and return generic strings like 'Error: {str(e)}' without indicating whether the error is retryable, user-fixable, or fatal. Pattern 'recovery-guide' requires actionable error messages.
High: No pagination support documented. list_book_prices, list_quizzes, list_study_resources, list_available_diseases do not expose page/offset/limit parameters or return total_count. Without pagination, large result sets will exhaust context windows. Pattern 'paginated-result' calls for structured pagination.
Medium: Tool composition incomplete. Multi-disease scraping (scrape_multiple_diseases) lacks documented per-item success/failure. If 5 of 10 diseases fail, the tool returns a single bulk error rather than per-item status, forcing the agent to retry everything. Pattern 'response-shaper' calls for per-item results on batch operations.
Medium: Chaining IDs missing from responses. scrape_disease returns disease info but does not document whether the response includes 'disease' field for subsequent get_disease_references calls. Broken chaining forces extra lookup calls. Pattern 'tool-chain' requires downstream IDs in output.
Medium: Authentication tools return demo/placeholder data. complete_browser_auth always succeeds and returns a hardcoded demo user instead of validating the code against pending OAuth states. This circumvents real security checks and invites misuse in production. Pattern 'permission-gate' requires actual authorization verification.
Medium: No rate limiting or timeout documentation. scrape_* tools depend on external Puppeteer services with TIMEOUT_MEDIUM constants, but no tool description mentions timeouts, retry behavior, or rate limits. Agents may trigger runaway scraping loops. Pattern 'tool-gateway' calls for explicit timeout and rate limit guidance.
Low: Confirmation/dry-run pattern absent for destructive tools. write_to_sheet and complete_browser_auth modify state but lack dry-run or confirmation steps. Agents may make irreversible changes. Pattern 'confirmation-request' recommends confirm-before-execute for write operations.