An MCP server that implements Authentication and Authorization with Streamable HTTP and communicates with a local sqlite database.
Server defines 5 tools with explicit input and output schemas using Zod. All tools have descriptions and are registered in src/tools.ts. Input schemas are properly typed with Zod and converted to JSON Schema. Output schemas are documented. However, parameter descriptions are entirely missing, the Zod schemas define the structure but provide no human-readable guidance for what each parameter means or how to use it. Tool names follow verb_noun convention well. Error handling is basic (throw) with no recovery guidance. Tool descriptions are adequate (110-180 chars) but lack dependency hints or prerequisites.
Add a new TODO item to the list. Provide a title for the task you want to add. Returns a confirmation message with the new TODO id.
Mark a TODO item as completed. Provide the id of the task to mark as done. Returns a confirmation message or an error if the id does not exist.
Delete a TODO item from the list. Provide the id of the task to delete. Returns a confirmation message or an error if the id does not exist.
List all TODO items. Returns a formatted list of all tasks with their ids, titles, and completion status.
Update the text of a todo
Parameter descriptions entirely missing. Zod schemas define input types (title: string, id: number, text: string) but provide zero human-readable guidance. LLMs cannot infer semantic meaning from type names alone, e.g., 'id' could be numeric PK or external reference; 'text' vs 'title' distinction is unclear.
Tool 'updateTodoText' violates verb_noun naming convention (should be 'update_todo_text'). Inconsistent camelCase breaks agent discovery patterns and wastes LLM reasoning cycles comparing tool names.
Error handling returns raw thrown errors without recovery guidance. A delete_todo call with invalid id will throw but provides no hint like 'Try list_todos() first to find valid IDs.' LLMs receive unactionable errors.
Inferred effective spec: 2026-07-28+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 70 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 57 | - | v1 |
Destructive tool (delete_todo) lacks confirmation step or dry-run pattern. Agents cannot preview consequences before executing permanent deletion.
Output schema documented in code but not exposed via tool registration. The outputSchema field is present in tool definition but may not be transmitted to the client if the MCP server is not exposing it through the protocol properly.