MCP server for Homebox inventory management system
The Homebox MCP server provides 17 well-structured tools with consistent naming conventions and reasonable descriptions. Tool names follow verb_noun patterns (get_*, create_*, update_*, delete_*, search_*) which is correct. All tools have descriptions that exceed the 20-character minimum. However, there are significant gaps in schema completeness, parameter descriptions, and error handling guidance. Most tools lack detailed output schema documentation, and several parameters lack descriptions or proper type constraints. The server handles credentials correctly via environment variables (HOMEBOX_API_KEY, username/password) rather than exposing them as tool parameters. Token refresh logic and authentication mode selection are well-implemented. Overall, this is a functional inventory management tool suitable for basic use but lacking the polish and error guidance expected of production-grade toolkits.
Create a new item in Homebox
Create a new label in Homebox
Create a new location in Homebox
Delete an item from Homebox
Delete a label from Homebox
Delete a location from Homebox
Get detailed information about a specific item by ID
Missing output schema documentation for all tools. While the code processes responses (formatItemResponse, formatLocationResponse), the MCP tool registration does not declare the expected return type structure. LLMs cannot plan multi-step tool chains without knowing what fields are returned.
No error handling guidance in tool descriptions. Destructive tools (delete_item, delete_location, delete_label) lack any mention of confirmation, dry-run capability, or what the agent should do if deletion fails. Create/update tools do not document what validation errors are possible or how to recover from them.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
Search for an item and return a direct web link to it
Get all items in Homebox inventory, with optional filtering by location
Get detailed information about a specific label
Get all labels in Homebox
Get detailed information about a specific location
Get all locations in Homebox
Search for items in Homebox by name, asset ID, serial number, or other fields
Update an existing item in Homebox
Update an existing label in Homebox
Update an existing location in Homebox
Pagination and result limits not documented. Tools like get_items and search_items do not declare maximum result size or whether pagination is supported. The code contains no visible pagination parameters (limit, offset, cursor), so returning large datasets could overflow the LLM context window.
Parameter 'color' in create_label and update_label lacks format constraint. Description says 'hex code' but provides no enum, regex pattern, or validation guidance. LLMs may pass invalid hex strings; error message would need to guide correction.
No idempotency guarantees documented. Create and update tools do not state whether repeated calls with identical parameters are safe. Agents may retry on ambiguous network failures, risking duplicate items or locations.
No tool annotations for risk levels. The rubric notes tools can declare readOnlyHint, destructiveHint, and idempotentHint. This server does not expose these in tool definitions, preventing client-side safety features like confirmation prompts or audit logging.