AI Assistant MCP Server using FastMCP with modular architecture for tour booking, flight search, weather information, and semantic tour package search
The server provides 5 tools with reasonable naming (verb-first style) and basic schema structure. However, multiple critical gaps reduce quality significantly: (1) Parameter descriptions are present but minimal, many lack guidance on constraints, valid values, or format expectations. (2) Output schemas are not documented in the source; responses are mentioned in implementation but not formally declared. (3) Error handling is implemented in code (e.g., create_booking returns structured error dicts with action guidance), but error classification (retryable vs. user-fixable vs. fatal) is not explicit. (4) Tool descriptions range from 110 - 220 chars, within acceptable bounds, but lack LLM-optimized structure, e.g., search_tour_packages fails to mention that 'IGNORED' parameters should be removed, which is confusing. (5) One tool (search_tour_packages) documents parameters as 'IGNORED for compatibility,' which is a red flag suggesting broken or legacy design. (6) No tool annotations (readOnlyHint, destructiveHint, idempotentHint) present. (7) Security concerns: Supabase keys loaded from env, but no explicit secret-injection pattern declared in schema. Overall: functional baseline, but lacks polish and LLM-optimization needed for production agent use.
Create a new tour booking with user phone, package ID, number of people, and optional special requests. Automatically creates user if not exists, validates package availability, calculates total amount, and updates available slots.
Get current temperature and weather conditions for a city using OpenWeatherMap API. Returns temperature in Celsius, feels-like temperature, humidity percentage, and weather description. All times are in Vietnam timezone (UTC+7).
Get weather forecast for a city for the next 1-5 days using OpenWeatherMap API. Returns daily aggregated forecast with temperature ranges, weather conditions, humidity, and rain probability. All times are in Vietnam timezone (UTC+7).
Search for flights between two airports using AviationStack API. Converts all times to Vietnam timezone (UTC+7) and returns formatted flight information including departure, arrival, airline, and flight duration.
Search for tour packages using semantic vector search with OpenAI embeddings and cosine similarity matching. Returns tour packages that semantically match the user's query without applying filters, allowing the agent to decide relevance.
search_tour_packages has 4 of 5 input parameters marked 'IGNORED - parameter kept for compatibility'. This is a broken schema design: either remove these params or document why they are present. LLMs will attempt to use them, causing confusion.
No output schemas are documented for any of the 5 tools. The source code comments describe return types (e.g., 'Returns tour packages...', 'Returns formatted flight information...'), but these are not formally declared as JSON Schema. LLMs cannot infer response structure, leading to hallucination of fields.
Parameter descriptions lack explicit constraints. E.g., 'number_of_people' description says 'must be positive integer' but JSON Schema has no minimum constraint. 'limit' param says '1-100' in description only, not in schema. This forces LLMs to parse natural language for constraints, increasing error likelihood.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 56 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 49 | - | v1 |
Error handling is implemented in code (create_booking returns detailed error dicts with 'success', 'error', 'action' fields), but error classification is not explicit. Tool descriptions do not mention retryable vs. user-fixable vs. fatal errors, leaving LLM uncertain how to respond to failures.
No tool annotations present (readOnlyHint, destructiveHint, idempotentHint). create_booking is marked Risk: WRITE in metadata but no destructiveHint annotation in schema. Tool annotations help agents reason about side effects and retry safety.
Security: Supabase keys loaded via environment variables (SUPABASE_URL, SUPABASE_KEY). Code checks they are configured, but no explicit pattern declared for secret injection. Tool description should not mention these credentials, and server should validate they are present at startup (already done in code, but not declared in protocol).
search_tour_packages description is confusing. It states 'without applying filters, allowing the agent to decide relevance,' but the schema accepts max_price, duration, destination params (marked IGNORED). This suggests the tool ignores user-provided filters, which is poor UX.