MCP server for Type 1 Diabetes management with CGM data integration, insulin dosage calculation, community search, and sick day guidelines
Mixed quality across 7 tools. All tools have descriptions (good baseline), but parameter documentation is inconsistent. Schemas are present but lack depth, most parameters have type and description, but error handling is weak, and several tools expose secrets as parameters (critical security issue). Naming is clear and verb-based. Tool purposes are stated, but descriptions sometimes lack actionable 'when to use' guidance. Output schemas are not formally documented. Two critical security flaws: get_dexcom_auth_url, get_cgm_sandbox, and get_cgm_with_token all accept OAuth secrets (client_secret) as parameters, violating pattern:secret-injection. This is a hard blocker for production use.
Analyze sick day risks and retrieve clinical guidelines based on patient status. Use this tool when the user reports being unwell. It returns evidence-based recommendations (JSON) from ISPAD/ADA guidelines to help the LLM generate safe and personalized medical advice.
Calculate suggested insulin bolus dose for Type 1 diabetes management. This tool calculates both correction dose (for high blood glucose) and meal dose (for carbohydrate intake) using standard formulas. Use this when a user asks: - "How much insulin should I take?" - "Calculate my bolus for this meal" - "I need to correct my high blood sugar"
Get CGM data using OAuth token from HTTP header (PlayMCP integration). This tool automatically retrieves the Dexcom access token from the Authorization header, which is passed by PlayMCP after OAuth authentication. Use this when: - User asks "혈당 보여줘" or "what's my glucose?" - User wants to check recent CGM readings
Get CGM data from Dexcom Developer API Sandbox using authorization code. This tool uses the official Dexcom API (not Share API) and works with the Sandbox environment, which provides simulated CGM data for testing.
CRITICAL: OAuth secrets (client_secret) exposed as tool parameters in get_dexcom_auth_url, get_cgm_sandbox. Secrets in parameters leak into logs, LLM traces, and user-facing output. Violates pattern:secret-injection.
Output schemas not documented for any tool. LLMs cannot plan field extraction or multi-step tool chains without knowing response structure. Tools return markdown strings (get_dexcom_auth_url, get_cgm_sandbox, get_cgm_with_token, get_cgm_data), hard to parse downstream.
Numeric parameters lack bounds documentation. calculate_insulin_dosage accepts current_bg and target_bg (integers) with no specified valid range (e.g., 40 - 400 mg/dL for realistic glucose). Without bounds, LLMs may pass invalid values.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 60 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 57 | 2025-03-26+ | v1 |
Get CGM data using an existing access token. Use this if you already have a valid access token from a previous OAuth flow.
Generate Dexcom OAuth authorization URL for Sandbox environment. Use this to get the URL where users can authorize your app. In Sandbox mode, no password is required - users select from a dropdown.
Search Korean blogs and web pages for Type 1 diabetes patient experiences and tips. Use this tool to find real-world advice from the diabetes community, such as: - Low blood sugar snack recommendations - CGM sensor patch tips - Travel advice for diabetics - Daily life management tips
Error handling lacks recovery guidance. Most tools return error strings but do not tell the LLM what to do next (e.g., 'Call get_dexcom_auth_url first', 'Retry with different parameters'). Only get_cgm_with_token provides actionable 401 guidance.
No dry-run or confirmation pattern for tools that modify state or trigger OAuth flows. Destructive medical advice (e.g., insulin dose calculation mistakes) should support a 'preview' or 'confirm before execute' step. Tools lack hints (destructiveHint, readOnlyHint) in their metadata.
Tool descriptions lack context on when to use vs similar tools. search_diabetes_community does not explain how it differs from or complements other knowledge sources (e.g., clinical guidelines from analyze_sick_day_guidelines). LLMs may not choose the right tool.