A Node.js/Express backend server for the AllStrides running events management platform. Provides REST APIs for user authentication, event management, RSVPs, ratings, voting, and real-time WebSocket chat. Uses SQLite database via Sequelize ORM.
Scoring was not performed
Tools 13-14 (get_maps_mcp_toolset, get_bigquery_mcp_toolset) are Python utility functions, not MCP tool definitions. No input schema visible, no JSON Schema structure, no MCP registration pattern. These appear to be helper functions misidentified as tools.
Output schemas completely undocumented across all tools. LLMs cannot plan downstream calls or extract needed fields without knowing response structure. No documentation of pagination cursors, total counts, or result limits.
No permission checks or scope declarations documented. Sensitive write operations (register, create_event, vote_on_event, rate_event) lack confirmation or authorization documentation. No mention of who can call these or what permissions are required.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 25 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 33 | - | v1 |
Event ID type inconsistency: vote_on_event, rsvp_to_event, rate_event expect event_id as 'number', but get_event_detail accepts 'id' as 'string'. This breaks tool chaining, output of get_event_detail cannot flow into vote_on_event without type coercion.
Minimal parameter constraints. No enums on unit parameter (create_event). No min/max on distance, skip, limit. No format constraints on email, start_time (ISO format mentioned but not enforced as description). Agents will hallucinate invalid values.
Descriptions for vote_on_event and rsvp_to_event are extremely terse (45-50 chars). They do not explain when to use these vs other event tools, what toggle behavior means for vote, or whether RSVP response is immediate or requires confirmation.
No error handling guidance in any tool description. No mention of what happens on permission denied, resource not found, validation failure, or duplicate registration. LLMs cannot self-correct without actionable error responses.
Inconsistent naming convention: mix of snake_case (get_current_user, list_events) and hyphenated (reset-password-request). MCP tools should use consistent verb_noun_noun_* format.
get_current_user and update_current_user require authentication context but this is not documented in tool descriptions. Unclear if 'current' is inferred from JWT or passed as parameter.