First Basic MCP Agent with Gemini - a multi-server MCP orchestration system that connects multiple MCP servers (math, weather, shell execution, news feeds) to a Gemini LLM agent
This server has significant gaps across naming, descriptions, and schema quality. Of the 14 tools, most have acceptable descriptions but weak input validation. Critical issues: (1) execute_shell_command accepts dangerous shell injection input with no validation or filtering; (2) Mathematical tools (add, subtract, multiply, etc.) have minimal descriptions lacking context about when to use them vs alternatives; (3) Weather tools lack error handling for invalid cities; (4) No per-parameter descriptions for optional parameters like max_results default behavior; (5) Output schemas are not documented for any tool, agents cannot plan downstream calls; (6) No idempotency guarantees stated; (7) Error handling is generic (try/except) with no guidance for LLM recovery.
Fetches the latest news articles from FreeCodeCamp's news feed.
Add two numbers
Divide two numbers
Execute a shell command provided in natural language
Calculate the factorial of a number
Fetches the latest YouTube videos from FreeCodeCamp's YouTube channel.
Returns a secret message from FreeCodeCamp.
execute_shell_command accepts untrusted input with no sanitization or validation, creating command injection vulnerability. A malicious LLM or prompt injection can execute arbitrary commands (e.g., `rm -rf /`). No allowlist, no blocked-command filtering, no AST parsing.
Mathematical tools (add, subtract, multiply, divide, power, sqrt, factorial, modulus) lack output schema documentation. LLMs cannot plan downstream use of results or extract specific fields. Descriptions are generic one-liners (19-50 chars) that do not explain when to use each tool vs alternatives or document special cases (division by zero, negative sqrt, overflow).
Tool naming violations: 'FreeCodeCamp News Fetcher' and 'freecodecamp_secret_msg' do not start with action verbs. Should be 'fetch_freecodecamp_news', 'list_freecodecamp_news', 'get_freecodecamp_secret_message'. This breaks the pattern:tool convention and forces LLMs to reason harder about tool intent.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 46 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 42 | - | v1 |
Get the current weather for a given city
Get the current weather for a given city using wttr.in (no API key required)
Calculate the modulus of two numbers
Multiply two numbers
Raise a number to the power of another
Calculate the square root of a number
Subtract two numbers
No output schema documentation for any tool. Agents cannot infer what fields are returned, what types they are, or what downstream tools can accept them. Weather tools return unspecified structures; news tools return 'title' and 'URL' inferred from code, not declared.
Pagination not documented for tools returning lists (FreeCodeCamp News Fetcher, fetch_freecodecamp_youtube_videos). max_results=5 is hardcoded; no offset/cursor mechanism. If results exceed max, LLM has no way to fetch next batch. Violates pattern:paginated-result.
Error handling is generic (try/except returning 'Exception occurred') with no recovery guidance. Agents cannot distinguish retryable errors (timeout, transient network) from fatal ones (invalid input). Weather tools return no guidance for 'city not found', should suggest alternatives or clarify format.
Parameter descriptions lack constraint information. max_results, page_size, numeric bounds (exponent range, n bounds for factorial), string format (city name vs code), and enum validation are not documented. LLMs guess at valid ranges and formats, leading to invalid invocations.
Weather tools do not document API dependencies or rate limits. If OpenWeatherMap API is used, quota exhaustion can cause failures. No fallback or degradation strategy documented (get_weather_wttr is a fallback, but this is not stated in get_weather).
No idempotency guarantees. Math tools are inherently idempotent (add(2,3) always returns 5), but this is not stated. Shell command execution is NOT idempotent, running 'rm file.txt' twice will fail on the second call. No documentation of side effects or repeatability.
freecodecamp_secret_msg tool lacks purpose and clarity. Description is vague (40 chars). No documentation of when/why to call it or what the 'secret' message is used for. Appears to be a demo/placeholder tool that should be removed or properly documented.