MCP server for AI image generation via Google Gemini
Single tool 'generate_image' has a well-structured schema and comprehensive description, but lacks critical error guidance patterns and security best practices. The tool definition is explicit and visible in src/index.ts with proper JSON Schema input validation via Zod. Description is detailed (194 chars), exceeding the 10-char minimum and within the 10-1024 baseline range. However, the tool accepts an API key as a parameter (google_api_key), violating secret-injection patterns. No error handling guidance is provided to the LLM about recovery paths (e.g., 'if blocked, try a different prompt'). The schema itself is well-typed with proper descriptions for each parameter, including optional flags and defaults. Output is returned as structured ToolContent[] with inline images and summary text.
Generate or edit images using Google Gemini. Provide a text prompt describing what you want. Optionally include one or more reference images to inform the output (e.g. edit a photo, restyle an icon, combine references).
API key exposed as tool parameter (google_api_key). Credentials must never appear as tool parameters; use server-side secret injection via environment variables or vault. Agent traces log every parameter, secrets in params leak into logs and context.
No error recovery guidance in tool description or return format. LLM cannot determine what to do when generation is blocked or fails. Error responses do not explain next steps (e.g., 'Generation blocked: CONTENT_POLICY. Try rephrasing without [content type]').
No confirmation or dry-run pattern for an operation that consumes API quota and has side effects (generates and optionally saves images). Agents making mistakes cannot be prevented.
Tool description uses example syntax ('e.g. edit a photo, restyle an icon, combine references') instead of declaring supported input patterns as constraints or enums. LLMs may over-generalize beyond the intended use cases.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 69 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 47 | - | v1 |