HTTP API wrapper for AI Vibes Radar MCP Server that exposes brand perception analysis tools via HTTP API for web app integration
This HTTP wrapper server exposes 4 tools via Express, but falls significantly short of production-grade definition quality. Tools lack input validation, parameter descriptions are minimal or missing, output schemas are undocumented, error handling is generic, and critical security issues exist (API keys passed via environment without validation, no rate limiting, no permission checks). The 'analyze' tool delegates to external LLM APIs (OpenAI, Anthropic) with no structured output validation or recovery guidance. The 'compare' tool has no visible implementation. Naming is reasonable (verb_noun pattern) but descriptions are under 100 chars and lack context for LLM selection. No tool annotations (readOnlyHint, destructiveHint, idempotentHint) despite read-only semantics. Parameters lack type enforcement, 'depth' in analyze is a free-form string with no enum constraint. The server conflates HTTP API design with MCP tool definition and does not follow MCP schema patterns.
Analyze brand perception including sentiment, attributes, competitive positioning, innovation score, trust score, sustainability score, and value perception score
Compare brand perception analysis results between two brands, determining a winner based on consensus scores
Health check endpoint that returns service status, name, version, and timestamp
Retrieve brand analysis reports from database, ordered by most recent first
compare tool has no visible implementation in server.js, only endpoint stub. Tool definition is inferred, not explicitly registered with schema.
analyze tool has no documented output schema. LLMs cannot predict the structure of the response (models, consensus, scores) without explicit documentation.
Parameter 'depth' in analyze tool is free-form string with no enum constraint. Description does not specify valid values (standard, detailed, quick, etc.). LLMs will hallucinate invalid depth values.
No parameter type definitions visible for reports tool 'limit' parameter, assumed integer but not formally declared. 'brandName' in URL path not formally documented as required.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 35 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 36 | - | v1 |
Error handling is generic (500 'Failed to analyze brand: <error.message>'). Does not classify errors as retryable, user-fixable, or fatal. Does not guide LLM recovery (e.g., 'If LLM API quota exceeded, retry in 60 seconds').
No tool annotations present. 'health', 'reports', 'analyze', and 'compare' should be marked with readOnlyHint=true. 'compare' has no idempotentHint despite being safe to retry.
Supabase and OpenAI/Anthropic API keys injected via environment variables but no validation that they are present before server starts. Missing keys cause runtime failures with unhelpful error messages.
No rate limiting on /analyze endpoint. An agent in a retry loop could spawn hundreds of parallel OpenAI/Anthropic API calls, causing runaway costs and service exhaustion.
No pagination limit documented in reports tool. 'limit' defaults to 10 but max is not enforced, a malicious or confused LLM could request limit=10000, exhausting memory and context.
health endpoint returns verbose metadata (service name, version, timestamp) that could be stripped for token efficiency, but more critically, response schema for all tools is undocumented.