MCP server for Postiz social media management platform. Provides tools to create posts, retrieve integrations, and query posts within date ranges.
Server has 3 well-named tools with clear verb-noun structure (create_post, get_integrations, get_posts). All tools have descriptions and input schemas present. However, output schemas are not documented, parameter descriptions lack detail regarding constraints and formats, and error handling guidance is minimal. The server uses Zod for schema definition but relies on imperative tool registration in server.js rather than declarative schema exports, making verification of full schema compliance difficult without inspecting handler implementations.
Create a new social media post on Postiz platform
Get all connected social media accounts and integrations configured in your Postiz workspace
Retrieve posts from Postiz within a date range
Output schemas not documented. No type definitions or field descriptions for tool responses. LLMs cannot plan downstream calls or extract required data.
Parameter descriptions lack format constraints and validation rules. E.g., date parameter says 'ISO 8601 format' but does not enforce it in schema or describe error handling for malformed dates. Integration_id has no guidance on how to obtain one beyond 'use get-integrations'.
No pagination parameters or limits documented for get_posts. Query returns unspecified result size; no stated limit or offset/cursor. Large result sets will exhaust context window.
Error responses not structured for LLM recovery. No indication of which errors are retryable, user-fixable, or fatal. create_post does not warn about side effects (irreversible publish action), nor does it offer dry-run/confirmation pattern.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 71 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 37 | - | v1 |
API key exposed in axios header without explicit masking in logs. Core/server.js logs 'API Key: Available' but does not document that parameter-level secrets are never acceptable. Audit trail for tool calls not visible in provided source.
Chaining IDs not guaranteed in responses. create_post returns unspecified structure; if it doesn't return the created post ID or schedule ID, follow-up tools cannot reference the created resource without a lookup call.