An MCP server that provides tools for posting to Twitter/X, calculating BMI, fetching real-time data via Tavily, and code review prompts. Integrates with Google Gemini AI for chat-based agent interactions.
This server has significant gaps in definition quality. While all 4 tools are registered with schemas and basic descriptions, the descriptions are minimal (11-52 chars, below the 194-char baseline), and parameter descriptions are weak or missing. Tool naming lacks consistency (kebab-case mix with camelCase), and several tools have security/privacy concerns (hardcoded API keys in source, unclear side effects). Output schemas are not documented. Error handling is minimal. This is a typical community server landing in the C-D range.
Add two numbers
Calculate body Mass Index
Create a post on X formally known as Twitter
enter query and get real time information about anything
Hardcoded API key in source code (server/index.js, Tavily token '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'). Credentials must use server-side injection via environment variables or vault, not embedded strings.
All tool descriptions are extremely brief (11-52 characters vs 194-char baseline). Descriptions lack context on WHEN to use the tool, WHAT it returns, and any prerequisites. LLMs cannot reliably select these tools without expanded descriptions explaining differences and use cases.
Parameter descriptions missing or incomplete. 'status' in createPost has no description. 'query' in fetchRealTimeData has generic description. 'a' and 'b' in addTwoNumbers have minimal descriptions. LLMs cannot infer parameter semantics from names alone.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 35 | - | v1 |
No documented output schemas. Tool descriptions do not explain what fields are returned or what structure the LLM should expect. Output documentation is required so agents can plan downstream calls and extract correct data.
Tool naming inconsistency: 'addTwoNumbers' (camelCase), 'createPost' (camelCase), 'calculate-Bmi' (kebab-case with uppercase), 'fetchRealTimeData' (camelCase). Use consistent verb_noun naming convention (e.g. add_numbers, create_post, calculate_bmi, fetch_real_time_data) for LLM parsing.
createPost tool modifies state (posts to Twitter) but description does not explicitly state this is a destructive operation with side effects. LLMs need to know which calls are safe to retry and which are irreversible.
fetchRealTimeData has generic error handling (catches error and returns error.message). No guidance for LLM on recovery (e.g., 'Try a different query' or 'API rate limited, retry in 60 seconds'). Error responses must tell the agent what to do next.
Twitter API credentials stored in .env but no input validation on 'status' parameter. No checks for length limits, rate limits, or prohibited content. LLMs can be tricked via prompt injection into passing malicious payloads.