MCP server framework with OAuth 2.0 authentication, built on Hono with Stripe payment integration for premium tools
This server has 7 tools but source code only provides fragments of authentication/OAuth infrastructure and payment handling. Critical issue: actual tool definitions are NOT visible in the provided code. Files referenced (src/tools/me.ts, src/tools/personalGreeting.ts, src/tools/add.ts, src/tools/generateImage.ts, src/tools/search.ts, src/tools/fetch.ts, src/tools/premiumMath.ts) are not included. Additionally, visible code shows payment integration via Stripe but no evidence of tool schemas, parameter descriptions, or error handling guidance. The framework code (paidTool.ts, auth handlers) shows infrastructure but not the actual tools themselves. Conservative baseline applies: without visible definitions, cannot award credit for quality that might exist.
Tool definitions not visible in source code, all 7 tool files referenced but not provided. Cannot verify schemas, descriptions, or parameter definitions.
No tool descriptions visible. Without one, LLMs cannot determine when or why to select the tool.' Cannot assess description quality or LLM selectability.
No input schemas or parameter definitions visible. Free-form strings invite hallucinated values.'
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 24 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 14 | - | v1 |
No error handling guidance visible. Per pattern: 'Error responses must tell the LLM what to do next.' No evidence of recovery guides, error categorization (retryable/user-fixable/fatal), or actionable error messages.
Stripe payment integration (paidTool.ts) passes user email/username and Stripe secret key in function calls. Per security pattern: 'Credentials must never appear as tool parameters.' Secret injection should use environment variables only, never passed to registerPaidTool.
Tool 'greeting' (personalGreeting.ts) is ambiguous. Naming guideline: 'The tool name alone should convey what happens when called.' Does 'greeting' mean fetch a greeting, generate one, send one, or list available greetings? Conflicts with verb_noun pattern (should be verb_noun like 'generate_greeting' or 'send_greeting').
Tool 'me' is vague. What does it return? User profile? Current session? Auth status? Per naming rule: 'The tool name alone should convey what happens when called.' Better: 'get_current_user' or 'get_user_profile'.