MCP-compliant server with World ID authentication, providing human-in-the-loop authorization for AI agents through World ID proof verification
The server has 3 tools with proper registration and schema definitions using Zod. Tool descriptions are present and reasonably detailed (70-150 chars each). Input schemas are well-structured with type constraints and enums (e.g., verificationLevel). However, output schemas are completely undocumented, no return type descriptions appear in the source. Parameter descriptions are adequate but lack dependency hints and error guidance. The 'echo' tool is suspicious (echoes arbitrary input back; unclear purpose in a World ID auth context). Security is a strength (token-gating on sensitive operations), but composition is weak, tools are tightly coupled to World ID verification rather than composable for varied use cases.
Performs a privileged action requiring document/orb World ID verification
Returns the input message. Requires World ID session verification.
Verify a World ID proof to establish an authenticated session
Output schemas completely undocumented. No return type definitions visible for any tool. LLMs cannot plan downstream calls or extract fields without documented return structures.
Tool naming lacks clarity on return values and side effects. 'world-id.verify' returns a token; 'advanced-operation' is vague about what it actually does. Vague names cause LLMs to misselect tools.
'echo' tool purpose is unclear in context of World ID auth. Echoing input back after token verification appears to be a test/demo tool, not production functionality. Remove or rename to clarify intent (e.g., 'test-authenticated-request').
No error recovery guidance. Error responses mention validation failures but don't guide LLM on next steps. E.g., 'actionId mismatch' doesn't suggest whether to retry with corrected ID or call a discovery tool.
Inferred effective spec: 2025-06-18+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 71 | 2025-06-18+ | v2 |
| 2026-03-09 | F | 29 | - | v1 |
Parameter descriptions lack dependency hints. 'token' parameter on 'echo' and 'advanced-operation' doesn't explain it must come from world-id.verify first, or what happens if token is expired/invalid.
No pagination or result limits documented. Tools may return unbounded results; 'advanced-operation' description doesn't specify result shape or limits.