MCP server for managing and analyzing expenses stored in CSV format with AI-powered summarization capabilities
The Gastos server has 2 tools with mixed quality. Both tools have descriptions and input schemas, but several critical gaps exist: (1) tool names lack clear action verbs that distinguish function from data retrieval; (2) parameter descriptions in the schema are present but vary in quality; (3) no error handling guidance is provided, errors return raw exception strings rather than actionable recovery hints; (4) output schemas are undocumented, neither tool's response structure is formally specified; (5) parameter ranges and constraints are absent (e.g., 'dias' has no bounds); (6) the tools do not follow clear composition patterns (obtaining recent expenses should not require a separate tool when the data could be enriched in responses); (7) security issues: CSV file path is hardcoded with no validation against path traversal, and the agregar_gasto tool performs unvalidated file I/O. These are significant gaps for a production-grade MCP server.
Agrega un nuevo gasto al archivo data/gastos.csv. Parámetros: fecha (str | datetime): Fecha del gasto en formato 'YYYY-MM-DD' o como objeto datetime. categoria (str): Categoría del gasto. cantidad (float): Monto del gasto. metodo_pago (str): Método de pago utilizado. Retorna: str: Mensaje de confirmación o error.
Obtiene los gastos de los últimos N días para que la IA pueda generar un resumen. Parámetros: dias (int): Número de días a consultar (por defecto 5) Retorna: list: Lista de gastos de los últimos N días
No documented output schemas for either tool.
Parameter constraints missing; numeric bounds not enforced.
Error messages are raw exception strings, not actionable recovery guidance.
Tool names use Spanish; lack clear English action verbs.
Hardcoded CSV file path and no path traversal protection.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 39 | - | v1 |
No confirmation/dry-run mechanism for destructive write operation.
No pagination or result limits for obtener_gastos_recientes.