Minimal MCP server demo with paymcp (Stripe/Walleot) that generates image via OpenAI and exposes a paid generate tool over Streamable HTTP.
Single tool 'generate' has critical definition gaps. Tool name lacks an action verb (should be 'generate_image'). Description is present but minimal (47 chars). Input schema is visible but incomplete: uses Zod object without JSON Schema conversion, lacks parameter descriptions entirely, and has a @ts-ignore comment masking type safety issues. No documented output schema visible in the source. Error handling is absent, no guidance on failure modes (API quota, invalid prompts, network errors). Tool makes a WRITE operation (external API call, resource creation via image generation) but lacks error classification, retry guidance, or idempotency hints. The tool violates composition principle by combining image generation + resource exposure without clear separation of concerns. No input validation documented.
Generates high-quality image and returns it as MCP resource
Tool name 'generate' lacks action verb prefix. Should be 'generate_image' to signal intent clearly to LLMs. Current name is too generic and conflicts with common naming convention (verb_noun).
Input parameter 'prompt' has NO description. LLMs cannot infer what constitutes a valid prompt, length limits, or content constraints. Parameter descriptions are mandatory per pattern:tool-description.
Input schema uses Zod validation object without JSON Schema conversion. Line shows: inputSchema: { prompt: z.string() } with @ts-ignore comment, indicating the schema is malformed or not properly JSON Schema compliant. MCP requires valid JSON Schema with type, description, and optional constraints fields.
Tool description (47 chars: 'Generates high-quality image and returns it as MCP resource') lacks WHEN to use it, WHY to choose this tool, and WHAT happens. Does not answer: What is the cost? What are failure modes? How long does generation take? Too terse to guide LLM selection.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 46 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 47 | - | v1 |
No documented output schema. Code shows response returns content array with image object containing 'type', 'data', 'mimeType', 'annotations', but LLMs have no formal schema to understand result structure. Per pattern:tool, output schema is mandatory.
Tool is a WRITE operation (generates and exposes external resource via OpenAI API) but has ZERO error handling. No guidance on: API rate limits (quota exceeded), invalid prompts (too long, offensive content), network timeouts, OpenAI service outages. Per pattern:recovery-guide, errors must tell LLM what to do next.
Tool lacks idempotency hints and error classification. Calling generate with same prompt twice produces different images. No confirmation request or dry-run for expensive operations. Per pattern:confirmation-request, irreversible ops (especially costly ones) should require confirmation.
OpenAI API key is injected server-side (correct), but tool offers NO input validation. Accepts arbitrary prompt strings without length limits, content filtering, or safeguards. LLMs may pass offensive, excessively long, or nonsensical prompts, causing API errors.