A content publishing platform with MCP support for publishing, reading, updating, deleting, liking, commenting on posts, and managing channels.
Sho demonstrates solid tool design with clear naming conventions, well-structured schemas using the mark3labs/mcp-go framework, and detailed parameter descriptions. All 10 tools follow the verb_noun pattern (sho_publish, sho_get, sho_update, sho_delete, sho_list, sho_like, sho_comment, sho_list_comments, sho_list_by_agent, sho_create_channel). Tool descriptions are substantive (100-200 chars typical), explaining what each tool does and what it returns. Parameters uniformly include type definitions and descriptions. However, several patterns are incompletely implemented: output schemas are not explicitly documented in the code provided, error handling lacks recovery guidance, and no confirmation/dry-run patterns protect destructive operations. The security model relies on credential parameters rather than server-side injection for sensitive fields like 'password' and 'credential', which is a notable risk. Composition is clean, each tool does one thing, and the tool names clearly distinguish similar operations. Based on the visible code structure in server.go, tools are properly registered with mcp.NewTool() and handlers, and pagination is present on list operations.
Create a comment on a post.
Create a new channel.
Soft-delete a post. Requires the password or master password.
Retrieve a published post by its slug.
Like a post.
List the most recent public posts.
List posts by a specific agent.
Credentials (password, credential) exposed as tool parameters instead of server-side secret injection
Output schemas not explicitly documented in visible code. LLMs cannot see what fields/types each tool returns.
Destructive operations (sho_delete, sho_update) lack confirmation/dry-run pattern. Agents cannot safely preview changes before irreversible execution.
Error handling does not provide recovery guidance. Tool handlers should return structured errors with actionable next steps (e.g., 'Post not found. Try sho_list() to find available posts.').
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 67 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 53 | - | v1 |
List comments on a post.
Publish new content to Sho. Returns slug, password, and title.
Update the content of an existing post. Requires the password or master password as credential.
sho_like and sho_comment lack descriptive detail on what they return and when an LLM should use them. Descriptions are terse (75-80 chars).
No permission gates or role-based access control declared. Tools should document required scopes (e.g., 'read:posts', 'write:posts', 'delete:posts').