A collection of AI/ML projects including LangGraph workflows, voice-enabled chatbots, research agents, and MCP servers for bookmarks and weather
This repository is a collection of multiple prototype projects rather than a cohesive MCP server. Of the 5 tools identified, most lack proper parameter descriptions and all are either inferred from scattered implementations or lack complete schema visibility. The bookmark tools appear in a Next.js route file without explicit MCP registration visible. The Python tools in fine_tuning/tooling.py are defined as a simple dict without proper MCP SDK integration. No error handling guidance, no output schemas documented, and parameter descriptions are minimal or absent. This is a learning/research codebase, not production-grade tooling.
takes two numbers x and y and returns the sum of the given input that is x+y
creates a new bookmark for the authenticated user
Gets all bookmarks for the authenticated user
Takes a city name as an input and returns the current weather for the city
takes a command from the input and executes it
run_command tool accepts arbitrary OS commands with zero input validation. This is a critical security vulnerability, agents can execute destructive commands like 'rm -rf /', and there is no permission gating, no sandboxing, and no audit logging.
No output schemas documented for any tool. Callers cannot know what fields to expect. For example, get-user-bookmarks presumably returns a list of bookmarks, but the structure (fields, pagination, count) is undocumented.
Parameter descriptions are minimal or missing. 'titles' in create-user-bookmark, 'city' in get_weather, and 'command' in run_command lack context on format, constraints, or valid ranges. LLMs cannot infer proper usage from these sparse labels.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 44 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 30 | - | v1 |
No error handling or recovery guidance. If get_weather receives an invalid city name, the tool returns '404 not found', but there is no guidance for the LLM on what to do next (retry? ask user? search for similar city names?).
Tools are not registered via a standard MCP SDK. The Python tools are a bare dict in tooling.py; the bookmark tools are inferred from a Next.js route. Without explicit MCP SDK integration visible in the codebase, tool definitions cannot be verified to conform to the MCP schema spec.
No idempotent-operation support documented. If an agent retries create_user_bookmark due to network timeout, will it create a duplicate bookmark? The tool definition does not specify behavior on retry.
No pagination or result limits. If a user has thousands of bookmarks, get-user-bookmarks will return all of them, potentially exhausting the context window. No limit parameter or pagination cursor documented.
Tool composition is incomplete. The bookmark tools reference authentication ('authenticated user') but there is no tool to authenticate or manage sessions visible. It is unclear how the agent knows which user context to operate in.