MCP server implementation for OpenAI WebSearch with support for Chat Completions and Responses APIs
The server defines 2 tools with complete input schemas using Zod and explicit JSON Schema generation. Both tools have descriptions (194 and 181 chars respectively), well within the ideal 10 - 1024 range. Parameters are typed and mostly documented. However, output schemas are entirely undocumented, the tools return raw JSON from OpenAI without guidance on what fields the LLM should expect. Parameter descriptions are present but vary in quality; some (like 'Conversation messages') lack actionable detail about format constraints. No output field documentation, no pagination guidance, and error messages are generic. The server lacks tool annotations (readOnlyHint, destructiveHint) and does not guide the LLM on recovery strategies when API calls fail.
Perform a web search using OpenAI's Chat Completions API with search-enabled models
Perform a web search using OpenAI's Responses API with web_search_preview tool
Output schema not documented. Tools return raw JSON from OpenAI API without describing the response structure. LLMs cannot plan downstream calls or extract relevant fields reliably.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint). Both tools are read-only web search operations, but the LLM cannot infer this from the schema. Annotating these as read-only prevents unnecessary retry hesitation.
Error messages lack recovery guidance. When OpenAI API fails (invalid model, auth error, rate limit), the error thrown is a generic string. No indication of whether to retry, ask the user, or try alternative models.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 65 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
Parameter descriptions for 'messages' are generic ('Conversation messages'). Lacks detail: should specify role/content structure, max length, whether system messages are allowed in both tools (they differ: gpt-4o-search-preview includes 'developer' role; gpt-4o responses API shows only 'user|assistant|system').
No API secret injection guidance in description. The tools require OPENAI_API_KEY to be set in the environment, but there is no security note in the tool descriptions warning that this must be server-side injected, not passed as a parameter.
No pagination or result-size limits documented. Both tools return raw OpenAI API responses, which could be large. No guidance on limiting results, handling truncation, or requesting additional pages.