Multi-service MCP server providing tools for Canva design creation, Figma file manipulation, HubSpot marketing email management, MySQL database queries, CLI system diagnostics, and Codex workspace isolation
The Osoba MCP server suite has 23 tools spanning Canva, Figma, HubSpot, MySQL, CLI, and Codex. While most tools have descriptions and visible parameter schemas, there are significant quality gaps: (1) Many descriptions are generic and lack actionable detail for LLM tool selection. (2) Parameter descriptions are often minimal or missing ('field_type', 'offset', etc. lack context). (3) Error handling and recovery guidance are absent from tool specs. (4) Output schemas are not documented, LLMs cannot predict response structure. (5) Security concerns: HubSpot tools expose access_token as a parameter, violating secret-injection patterns. (6) Some parameter names are ambiguous (e.g., 'scope' in list_dir accepts only magic strings, not paths, but this constraint is buried in description). (7) No tool annotations (readOnlyHint, destructiveHint, idempotentHint) despite mixed read/write semantics. The server is functional but falls short of production-grade tool engineering standards.
Create a new Canva design. Use a standard preset (e.g. 'instagram_post', 'presentation', 'a4', 'youtube_thumbnail') or pass width + height + unit for a custom size. For brand template autofill, use the autofill_design tool instead.
Create a new marketing email in HubSpot. Requires a valid OAuth access token.
Create a new isolated workspace for Codex CLI execution.
Executes a read-only SQL SELECT query against the database and returns the results as a JSON string. IMPORTANT: Only SELECT queries are allowed. Do not attempt INSERT, UPDATE, DELETE, or other modifying queries.
Export a Canva design to a downloadable file. Submits an export job and polls until completion (or timeout). Returns a download_url when the export is successful.
Credentials exposed as tool parameters: HubSpot tools (create_hubspot_marketing_email, update_hubspot_marketing_email) require 'access_token' as a parameter. This violates secret-injection patterns, access tokens logged in traces/history leak credentials. Use server-side secret injection via environment variables.
Output schemas not documented. While input parameters have JSON schemas, no return-type documentation exists. LLMs cannot predict response structure, they must infer from descriptions or guess. Document the output schema (e.g., {id: string, title: string, url: string} for create_design). This is critical for tool chaining.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 52 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 13 | - | v1 |
Export Figma nodes as images, returning download URLs. The returned URLs are temporary (expire after a short time). Download them promptly.
Get all comments on a Figma file.
Extract the design system (tokens, components) from a Figma file. Traverses the node tree to collect color tokens, typography tokens, spacing tokens, and component metadata. Also extracts named styles.
Get the structure and metadata of a Figma file. The file_key is found in the Figma file URL: figma.com/file/{file_key}/...
Get specific nodes from a Figma file by their IDs.
Post a comment to a Figma file.
Retrieve detailed information about a specific Canva design.
Returns structured system health information: disk usage, platform, uptime. No arguments required. Safe — no user input reaches the OS.
Pin a workspace to prevent automatic cleanup/expiry.
List files in a workspace's artifact directory with metadata.
List designs in the authenticated Canva account. Returns paginated results. Use the next_page_token from the response to fetch additional pages.
Lists contents of an allowed directory scope.
Read a file from a workspace's artifact directory.
Reads the last N lines of a named log file from the logs directory.
Run Codex CLI within an isolated workspace with bounded resource constraints.
Returns systemd service status for an explicitly allowlisted service.
Update or archive an existing marketing email in HubSpot. Requires a valid OAuth access token.
Upload an image or video to the user's Canva asset library from a URL. The URL must be publicly accessible. Supported: JPEG, PNG, HEIC, GIF, TIFF, WEBP images (max 50MB) and M4V, MKV, MP4, MPEG, MOV, WebM videos (max 100MB via URL).
Missing tool annotations. Tools have mixed semantics (read/write/destructive) but no annotations to signal this to clients. Add readOnlyHint: true for reads (get_*, list_*), destructiveHint: true for deletes, and idempotentHint: true where applicable. This helps LLMs reason about retry safety and side effects.
Weak parameter descriptions. Many parameters lack actionable detail: 'scope' in list_dir says 'One of artifacts, logs, or scripts' but does not explain what each contains. 'depth' in figma_get_file says '1-4 recommended' but does not explain the performance/detail tradeoff. 'pages' in export_design says 'comma-separated page numbers' but does not clarify whether single pages export as separate files or merged. Add WHAT each option does and WHY the LLM might choose it.
No error handling or recovery guidance. Tools like execute_sql_query_tool (SQL injection surface) and run_codex (resource-intensive) have no documented error conditions, retry guidance, or constraints. What happens if the SQL query times out? If Codex hits memory limits? Add error classification (retryable vs fatal) and recovery hints.
Minimal descriptions for critical tools. get_design, figma_get_comments, keep_workspace have descriptions under 50 chars. Example: 'get_design' is 'Retrieve detailed information about a specific Canva design.', this does not explain when to call it vs list_designs, what fields it returns, or if it's needed before export_design. Rewrite with context: WHAT, WHEN, and WHY.
Ambiguous parameter semantics. execute_sql_query_tool accepts a 'query' parameter with no format validation or injection guards documented. Even though the description says 'SELECT only', an LLM could pass a DELETE statement. Add validation, sample valid queries, and make error messages actionable ('Invalid SQL: only SELECT queries allowed. Your query: DELETE FROM users, this is not permitted.').
Undocumented parameter dependencies. create_design has 'preset' and 'width'/'height'/'unit', if preset != 'custom', width/height are ignored. This is not stated explicitly. LLMs will pass both and waste tokens. Also, HubSpot tools have nested object parameters ('content', 'from_sender', 'to_recipients') with no example structure, LLMs cannot infer the schema.
No pagination guidance in list_* results. list_designs accepts page_token and limit, but the response structure is not documented. Does it return {designs: [...], next_page_token: '...'} or {items: [...], cursor: '...'}? Without this, LLMs cannot iterate through results reliably. Document response structure and clarify what limit=100 returns.
Missing generic names (process, run, do). 'run_codex' is borderline, what distinguishes it from 'create_workspace' and 'read_artifact'? Codex could mean several things. Rename to something explicit like 'execute_codex_cli' or 'run_codex_task_in_workspace' to clarify its purpose.