MCP Server for Slotix - AI-powered appointment management integration
SlotixMCP defines 18 tools with explicit schemas and descriptions visible in server.py. However, significant gaps limit production readiness. Naming is mostly clear (verb_noun pattern followed consistently), but parameter descriptions are sparse or missing entirely. Many tools lack actionable error handling guidance. Output schemas are not documented, the tool descriptions mention what fields *might* be returned, but don't provide a formal schema for parsing. Several parameters lack type hints or constraints (e.g., 'message' in send_notification is free-form; 'discount_value' in create_coupon has no min/max bounds). No tool includes error recovery guidance. Security concerns: no evidence of rate limiting, input validation, or permission checks. The server references a SlotixClient abstraction, but validation and sanitization logic is not visible in the provided code excerpt, making it impossible to verify defense against injection attacks.
Cancel an appointment. The appointment will be marked as cancelled (not deleted).
Create a new appointment for a client. Either client_name or client_id must be provided. If client_id is provided, client info is resolved from the database.
Create a new catalog item (service or product).
Create and send a discount coupon to one or more clients.
Get full details of a specific appointment. Returns: client info (name, contact, ID), date/time, duration, status, source, notes, services, payment info (total price, amount paid, method, notes, complete status), feedback (rating, comment, sentiment), and timestamps (created_at, updated_at).
Get appointments within a date range. Default: next 7 days. Use filters for specific dates or status.
Output schemas not documented. Tool descriptions list fields that 'might' be returned (e.g., get_appointment describes 'client info (name, contact, ID), date/time, duration...'), but no formal JSON Schema is provided for the response. LLMs cannot reliably parse or chain outputs without a documented schema.
Numeric parameters lack bounds. 'duration_minutes' in create_appointment, update_appointment, and create_catalog_item have no min/max constraints. 'discount_value' in create_coupon accepts 0-100 for percentage but description does not enforce this. 'validity_days' in create_coupon is unbounded. LLMs can pass absurd values (duration_minutes: 999999) that break API contracts.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 57 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
Get available time slots for booking appointments.
Get catalog items (services or products) with filtering options.
Get full details of a specific client.
Get list of clients. Optionally search by name, email, or phone.
Get your professional profile with all business details. Returns: name, email, phone, business info (name, address, city, postal code, country, VAT, website), localization (timezone, currency, language), booking settings (slot duration, notice hours, max days ahead, client modification rules, reminder times), enabled features (Telegram, WhatsApp, catalog, reminders, feedback, coupons, AI), coupon settings, and AI custom prompt.
Get business statistics and performance metrics.
Get all appointments scheduled for today.
Get all appointments for the current week (Monday to Sunday).
Reschedule an appointment to a new date/time and optionally notify the client.
Send a notification to one or more clients via their preferred channel (email, SMS, Telegram, WhatsApp).
Update an existing appointment (reschedule, add notes, change status, update payment). Returns updated appointment with all fields including timestamps.
Update an existing catalog item (service or product).
Free-form string parameters invite hallucinated values. 'message' in send_notification and reschedule_appointment, 'notes' in create_appointment and update_appointment, and 'description' in create_catalog_item are all free-text with no validation guidance. LLMs may pass markup, injection payloads, or invalid characters without constraint feedback.
Minimal error handling guidance. No tool description includes recovery paths (e.g., 'If appointment not found, try get_appointments() to list available slots'). Error responses are not visible in the provided code, but the tool definitions give LLMs no hint about what could fail or what to do next.
Destructive operations (cancel_appointment, update_appointment with status change) lack confirmation or dry-run support. Description states 'The appointment will be marked as cancelled' but offers no way for the agent to preview consequences or confirm intent. Agents may cancel bookings by mistake.
Mutually exclusive parameters not documented. 'create_appointment' requires 'either client_name or client_id', and 'send_notification' accepts 'client_id' or 'client_ids'. Descriptions state the constraint, but LLMs may pass both or neither without explicit validation errors visible. 'create_coupon' also has optional client_id vs client_ids but no enum or constraint structure.
No input validation or sanitization visible in provided code. The server references a SlotixClient abstraction (src/slotixmcp/client.py not shown), making it impossible to verify defense against SQL injection, command injection, or path traversal. Parameters like 'notes', 'message', 'search' are passed directly without visible filtering.
No rate limiting or timeout guidance. Tools that call external services (send_notification to email/SMS/Telegram/WhatsApp) have no documented timeout or retry policy. An agent in a loop could generate thousands of notification calls per minute.
No pagination or result limit enforcement visible in tool definitions. 'get_appointments', 'get_clients', and 'get_catalog_items' lack page/offset/limit parameters or documented caps. Large result sets (e.g., 5000+ appointments) would blow the context window and degrade LLM reasoning.
Security scopes and permission checks not declared. No tool description states what permissions or API capabilities it requires (e.g., 'read:appointments', 'write:notifications'). Audit logging, access control, and least-privilege configurations are not evident.