A FastMCP server for managing personal and shared expenses with MongoDB backend, supporting expense tracking, group management, member management, and expense splitting.
This server has 11 tools with significant quality gaps. Tools 1-4 are from main.py (no user_id filtering, unauthenticated). Tools 5-11 are from main1.py (with user_id, some authenticated). Major issues: (1) Duplicate tool names across files (add_expense, list_expenses, summarize appear twice) creates ambiguity and tool registration conflicts; (2) Parameter descriptions are minimal (10-30 chars typically) and lack format/constraint guidance; (3) No output schemas documented for any tool, responses are inferred from code but not formally declared; (4) No error handling guidance in descriptions; (5) Destructive operations (delete_expense) lack confirmation/dry-run patterns; (6) Date parameters use free-form strings with no format specification; (7) No pagination documented despite MongoDB aggregations returning potentially large result sets; (8) Field naming is inconsistent (user_id injected but tools still documented as accepting it as param). Per-tool analysis follows.
Add a new expense document for authenticated user. user_id is automatically injected by FastAPI gateway. Phase 0: Personal expenses Phase 1: Enhanced with optional group_id (for migration compatibility)
Add a new expense document. Triggered by natural language: "Add milk expense for 8 rupees today"
Create a new shared group. Creator automatically becomes admin.
Delete an expense for authenticated user. user_id is automatically injected by FastAPI gateway.
Get detailed information about a group including members. User must be a member of the group.
List all expenses for authenticated user in date range. user_id is automatically injected by FastAPI gateway.
Duplicate tool names (add_expense, list_expenses, summarize) across main.py and main1.py will cause tool registration conflicts. FastMCP cannot register two tools with the same name. Only the last registration will be active, silently breaking the first set of tools.
Parameter 'date' accepts free-form strings with no format specification. Code shows examples like 'Jan 1' and 'Jan 10' in docstrings, but no ISO 8601, regex pattern, or format constraint is documented. This invites LLM hallucination of invalid dates like '1st January' or '2024-13-01'.
No output schemas documented for any tool. Descriptions promise results (e.g., 'List all expenses', 'Summarize by category') but do not state the structure of returned objects. Code shows serialize(doc) returns {id, date, amount, category, ...}, but the response schema is not declared in tool metadata. LLM cannot reliably extract fields like 'id' for chaining.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 44 | - | v1 |
List all expenses in the date range. Example prompt: "List my expenses from Jan 1 to Jan 10"
List all groups user is a member of.
Initialize database schema and indexes. Call this once before using other tools.
Summarize spending by category. Example prompt: "Summarize my food expenses for this month"
Summarize spending by category for authenticated user. user_id is automatically injected by FastAPI gateway.
delete_expense (destructive operation) has no confirmation, dry-run, or undo pattern documented. Description does not warn the user or agent about irreversibility. No error guidance for 'expense not found' or 'already deleted' cases.
Parameter descriptions are extremely sparse (10-40 chars). Example: 'Start date for filtering expenses' is vague about format. Does it accept '2024-01-01', '01/01/2024', 'Jan 1', 'today', or a Unix timestamp? No constraints listed. LLM must guess, leading to invalid calls.
No pagination parameters documented on list_expenses or list_groups, despite MongoDB aggregation pipelines that can return arbitrarily large result sets. No limit, offset, page_size, or cursor documented. Large expense lists will blow the context window.
Tools document that user_id is 'automatically injected by FastAPI gateway', but the schema still lists user_id as an explicit parameter. This is confusing, if it's injected, why is it in the tool signature? Either remove it from the schema or clarify whether the LLM must provide it.
No error handling guidance. Tools return {'status': 'error', 'message': str(e)} on exception, but descriptions do not state what errors are possible or how the LLM should recover. Example: if delete_expense tries to delete a non-existent expense, what happens? 404? Silent success? LLM has no guidance.
setup_database has no clear precondition documentation. Description says 'Call this once before using other tools', but tools do not validate that setup_database was called first. If called out of order, which tool fails and with what error?
Tool composition: create_group returns group_id (inferred from code), but get_group_details requires group_id as input. The response schema is not documented, so the LLM cannot reliably chain create_group → get_group_details without a separate lookup.