A full-stack web application for travel blogging with user authentication, post management, and admin controls
Scoring was not performed
NOT AN MCP SERVER: This is a raw Express backend with no MCP protocol implementation. No @modelcontextprotocol/sdk imports, no stdio transport, no MCP tool registration. Cannot be used as an MCP server without complete rewrite to wrap handlers in MCP SDK.
Tool naming violates verb_noun convention. Names use camelCase suffixes like 'Handler' or expose implementation details ('signUpWithEmail' instead of 'create_user'). Per pattern:tool, names should start with action verbs for LLM clarity.
Output schemas are not documented. No return type specification visible in tool definitions. Per pattern:tool, LLMs need documented output structure to plan downstream calls and extract data.
Descriptions are generic and lack action context. Examples: 'Sign out the currently authenticated user...' is minimal; missing guidance on when to use vs alternatives. Per pattern:tool-description, descriptions must explain WHAT, WHEN, and prerequisites.
Parameter descriptions lack constraint details. Example: 'Password (required, minimum 8 characters, must contain uppercase, lowercase, digit, and special character)' is present but most others omit min/max lengths, regex patterns, or enum values. Per pattern:constrained-input, enums and formats must be explicit.
Error handling strategy not visible. No evidence of actionable error messages (e.g., 'Invalid category: got "travel", must be one of: nature, tech, lifestyle'). Per pattern:recovery-guide, errors must guide the LLM on next steps.
Destructive operations (deletePostByIdHandler, deleteUserHandler) have no confirmation/dry-run pattern. Per pattern:confirmation-request, irreversible ops should support a confirmation step to prevent agent mistakes.
JWT tokens exposed in descriptions. 'generates access and refresh tokens' implies tokens are returned in response, but source code excerpt is cut off. If tokens are in responses, they violate secret-injection pattern, tokens should never enter LLM context.
No pagination parameters documented for list tools (getAllPostsHandler, getAllUserHandler). Per pattern:paginated-result, list endpoints must accept limit/offset/cursor and return total count. Current definitions assume unbounded results.
Parameter type naming inconsistent. Example: 'userId' vs '_id' parameter naming. Per pattern:tool, parameter names should use consistent snake_case or explicit suffixes (user_id, user_name) to guide LLM selection.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 0 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 27 | - | v1 |