The server defines 3 tools with Zod schemas and descriptions, but quality is uneven. All tools have descriptions and basic schemas, but naming conventions are weak (verb_noun pattern not consistently followed), parameter constraints are underspecified, and error handling lacks actionable recovery guidance. The generateImage and generateVideo tools have comprehensive parameter lists but descriptions are in Chinese and some parameters lack clear constraints (e.g., sample_strength range stated in text but not in schema, model names should be enums). The hello tool is trivial. No tool annotations present. Error responses are generic.
即梦AI图像生成工具,支持文本到图像生成以及图像混合/参考图生成
即梦AI视频生成工具,支持文本到视频生成以及首尾帧图片引导生成
一个简单的问候工具
Weak naming conventions: 'generateImage' and 'generateVideo' use camelCase instead of snake_case verb_noun pattern. These names are action-oriented but do not follow production baseline conventions from 549+ tools where 90% of A+ tools use verb_object patterns like 'generate_image', 'create_video'. Additionally, 'hello' is generic and does not clearly indicate it is a greeting tool. The naming should reflect the action clearly from the tool name alone.
Model parameter for generateImage and generateVideo lacks enum constraint. The description lists valid values (jimeng-5.0, jimeng-4.6, etc.) as plain text, but Zod schema defines it as z.string().optional() without enum validation. This allows LLMs to hallucinate invalid model names. Should use z.enum([...]) to enforce constraints at schema level.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 39 | - | v1 |
Parameter constraints not enforced in schema: sample_strength described as 'range 0-1' but schema uses z.number().optional().default(0.5) without .min(0).max(1). width and height default to 1024 but have no documented max bounds (should enforce reasonable limits like max 2048 to prevent API abuse or timeout). resolution parameter in generateVideo lists '720p' or '1080p' as enum options in text but schema is z.string().optional() without enum.
Error handling lacks recovery guidance. Error responses return bare messages like '图像生成失败: [errorMessage]' or '视频生成失败:未能获取视频URL'. The LLM cannot determine if the error is retryable, user-fixable, or fatal. For example, if the API token is invalid, the error should suggest 'Check that JIMENG_API_TOKEN is set correctly' rather than a generic failure message.
Descriptions are in Chinese, which may reduce LLM comprehension when the server is used in English-speaking contexts. 'hello' description is '一个简单的问候工具' (a simple greeting tool), acceptable but brief (5 chars in English equivalent). generateImage/generateVideo descriptions are ~80+ chars in Chinese but lack clear WHEN-TO-USE guidance that arcade patterns recommend.
No tool annotations present. The MCP SDK supports readOnlyHint, destructiveHint, and idempotentHint. generateImage and generateVideo are WRITE/destructive operations (they call external APIs and consume tokens), but no annotation is present in the code to signal this to the client. hello is READ_ONLY but not annotated.
Secret injection incomplete: refresh_token parameter in generateVideo is marked optional and described as 'usually from environment variables', but the schema accepts it as a tool parameter. This is a potential security risk, credentials should never appear as parameters. The server should read JIMENG_API_TOKEN and other secrets from env vars only, not accept them as tool inputs.
filePath parameter in generateImage accepts local paths ('本地图片路径') but no validation or sanitization is visible in the code. This opens a potential path traversal vulnerability if the server runs with insufficient file system isolation. The code should validate that filePath does not contain '..' or absolute paths to prevent accessing unintended files.