A React + TypeScript web application for AI-powered document generation, featuring tools for creating documents, PDFs, Word files, presentations, and stories using Google's Generative AI. Not an MCP server.
database-proxy tool is dangerously generic. Accepts raw table names and operations (select, insert, update, delete, rpc) without enum constraints or clear validation. LLMs could pass arbitrary table names and operations, creating security and usability problems.
No output schemas documented for any tool. LLMs cannot know what fields to expect from responses, forcing them to guess field names and blocking downstream tool chaining. This violates pattern:response-shaper and pattern:tool-chain.
Tool descriptions are truncated or vague. contact-form, edit-image, generate-book, generate-content, and generate-document descriptions lack actionable context. They do not explain when to use each tool vs. alternatives or what prerequisites exist.
Recommendations
Add explicit output schemas for all 9 tools. Document return field names, types, and what each field contains. Example: 'ai-chat returns {response: string, usage: {input_tokens: number, output_tokens: number}, timestamp: ISO8601}'. This enables chaining and prevents LLM field-name guessing.
Expand tool descriptions to 100-200 characters per pattern:tool-description. For each, add: (1) What does it do? (2) When should I use it vs. similar tools? (3) What prerequisites/permissions are needed? Example: 'chat-pdf: Analyze PDF documents with AI. Use when you have a PDF file and specific questions. Requires pdfContent as base64; max 5MB. Returns answer and confidence score.'
Add enum constraints to open-ended fields. Replace 'template: string' in generate-book with explicit enum: ["classic", "watercolor", "comic", "minimal", "vintage", "fantasy", "business"]. Replace 'action: string' in database-proxy with enum: ["select", "select_single", "insert", "update", "delete", "rpc"].
Refactor database-proxy into separate tools: list_database_records, create_database_record, update_database_record, delete_database_record. Each has a single action, explicit table enumeration, and clear return schemas. Current generic proxy violates pattern:tool (one responsibility per tool).
Add recovery guidance to error messages. Instead of 'Messages are required', return: 'Error: messages array is empty. Required format: [{"role": "user", "content": "..."}]. Pass at least one message to proceed.' This matches pattern:recovery-guide.
Parameter descriptions are minimal or missing context. Many parameters (e.g., 'editPrompt' in edit-image, 'bookDetails' in generate-book) lack constraints, formats, or LLM-friendly guidance. Descriptions should specify format, range, and what makes valid vs. invalid input.
No error handling guidance visible in tool definitions. Source code (ai-chat/index.ts) shows validation but returns generic error messages ('Messages are required', 'Maximum 50 messages allowed'). LLMs receive no recovery hints or next steps.
create-checkout-session and edit-image accept boolean flags (saveToGallery, saveToGallery) and enum fields (planType, billingPeriod, template) but descriptions do not clearly explain consequences of each option. This violates pattern:tool-description guidance to 'state WHAT the tool does, WHEN to use it'.
Parameter naming inconsistency. 'messages' (ai-chat) uses plural array, but other tools use singular nouns or nested objects (bookDetails, imageUrl). Inconsistent naming makes LLMs struggle with which parameter format to use across similar tools.
generate-book and generate-content accept nested object 'bookDetails' and free-form 'prompt' but lack enum or format constraints. LLMs have no way to know which 'template' values are valid (classic, watercolor, comic, etc.) without hardcoding knowledge.
generate-bookgenerate-content
Document parameter constraints in descriptions. E.g., for pdfContent in chat-pdf: 'Base64-encoded PDF file (max 5MB, .pdf only). Decode with Buffer.from(pdfContent, "base64") on client side.'
Clarify idempotency and side effects. State for each tool: Is it safe to retry? Does it modify state? E.g., 'create-checkout-session: Creates a new Stripe session (not idempotent, repeated calls create multiple sessions). Include idempotency_key in bookDetails to prevent duplicates.'
Unify parameter naming conventions. Use verb_noun for action params (e.g., databaseAction instead of action). Use type suffixes for IDs (e.g., user_id, file_id). Use plural arrays only for multi-item inputs (messages, filters), keep singular for scalars (topic, email).
Add batch variants for loops. If agents often call generate-content or generate-book in sequence, add generate-content-batch accepting array of prompts and returning array of results. This reduces token waste and latency per pattern:tool-chain.