MCP server for integrating with the Hevy fitness API, providing access to workouts, routines, exercises, and routine folders
Single tool 'getWorkouts' has adequate naming (verb_noun form) and clear description (33 chars, within range). Input schema is present with Zod validation and default values. However, the output schema is NOT formally documented, the tool returns a custom object with 'content' array and a 'workouts' field, but there's no schema definition visible for what 'workouts' contains. Parameter descriptions are minimal (generic 'Page number', 'Number of items'). Error handling exists but lacks recovery guidance. No tool annotations (readOnlyHint, etc.). The server exposes only 1 tool, limiting composition assessment.
Get user workouts with pagination
Output schema not documented. Tool returns a custom object with 'content' (array of text blocks) and 'workouts' (opaque structure), but the LLM has no schema definition for what fields exist in each workout object or what pagination metadata is returned.
Parameter descriptions are generic and lack constraint information. 'Page number (optional, default: 1)' does not specify bounds (e.g., minimum 1) or what happens if page exceeds available pages. 'Number of items per page' lacks a range (e.g., 1 - 100).
Error handling provides no recovery guidance. The tryCatch wrapper catches all errors and returns a ToolExecutionError, but the error message is not actionable, no hint about whether the error is retryable, what the valid input range is, or how to self-correct.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 48 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 50 | - | v1 |
No tool annotations present. Tool has no readOnlyHint, destructiveHint, or idempotentHint declarations per MCP spec 2026-07-28, limiting client-side optimization (e.g., caching, automatic retries).
Tool description does not specify result limits or pagination behavior. Baseline pattern requires pagination tools to advertise max results (e.g., 'Returns up to 100 workouts per page'). Without this, LLMs cannot predict whether large result sets will occur.
API key exposed in environment variable without validation that it is not logged or echoed. While not directly exposed as a tool parameter (correct), the client configuration does not document secret handling practices.