MCP server for HatchLoop AgentBroker. Exposes 23 operations for business discovery, verification, messaging, compliance screening, appointment booking, and transaction handling.
Agent Broker exposes 23 tools with significant definition gaps. While tool names follow verb_noun conventions and descriptions are present, the critical missing evidence is input/output schemas. The mcp.json snapshot provides high-level tool descriptions (50-150 chars, within baseline), but NO JSON Schema definitions are visible in the provided source code. Parameters are not documented with types, constraints, or format specifications. Error handling guidance is absent. Without schemas, LLMs cannot validate inputs or understand output structure, a fundamental failure for production readiness. The codebase shows implementation maturity (FastAPI, Docker, Cloudflare Workers edge architecture) but tool definitions are incomplete.
Place an outbound call to a business
Capture lead information and store in system
Check if a booking link is valid
Check TCPA/GDPR/CASL compliance and preview gating before send
Check quota status for rate-limited operations
Escalate conversation to human operator
Find real businesses by name, location, phone, or website
NO INPUT SCHEMAS VISIBLE: None of the 23 tools have visible JSON Schema definitions in the provided source. The mcp.json snapshot shows high-level descriptions but NO input parameter types, constraints, enums, or format specifications. Per hard scoring rules, all schema scores must be 0.
NO OUTPUT SCHEMAS DOCUMENTED: mcp.json descriptions do not specify return types, field names, or data structures. LLMs cannot plan downstream calls or extract structured data without knowing what fields are returned.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 52 | 2026-07-28+ | v2 |
Get conversation history for a specific interaction
Get outcome of a completed operation
Get status of an operation
Handle inbound communications
Import booking availability from URL (idempotent, returns same smb_id)
Search USASpending.gov for government contracts (read-only)
Map trade restrictions and compliance requirements by jurisdiction
Generate a new API key for a caller
Preview the cost of an operation before committing
Schedule appointments via Cal.com; imports 12 platforms
Screen against sanctions lists (OFAC, EU, UK) - read-only, quota-free
Test the connection and authentication
Send WhatsApp, SMS, email or voice to real businesses with TCPA/GDPR/CASL compliance built in
Send transactional confirmation messages
Verify a business on GLEIF LEI and SEC EDGAR directory lookups
Verify a company record via live registry lookup (read-only)
MISSING PARAMETER DESCRIPTIONS: Tool descriptions in mcp.json mention what tools do but do not enumerate or describe individual parameters. LLMs cannot understand what values to pass or which params are required.
VAGUE TOOL NAMES: 'handle_inbound', 'get_status', 'get_outcome' are generic. Does 'handle_inbound' parse messages, route to queues, or acknowledge receipt? Does 'get_outcome' return success/failure, metrics, or final state? Ambiguous names cause LLM selection errors.
NO ERROR HANDLING GUIDANCE: Descriptions do not tell LLMs what to do when a tool fails (e.g., 'business not found, try search_business() instead'). LLMs cannot recover from errors without explicit recovery paths.
SECURITY: send_message and call_business descriptions do not mention TCPA/GDPR/CASL compliance checks. The payment config notes 'compliance built in', but tool descriptions omit prerequisites, constraints, or warnings about when these tools can/cannot be called.
IDEMPOTENCY UNCLEAR: 'import_booking_url' description says 'idempotent, returns same smb_id', but other write tools (capture_lead, schedule_appointment, call_business) do not declare idempotency. LLMs cannot safely retry without this guarantee.
PAGINATION MISSING: 'find_business', 'lookup_us_contracts', and 'get_conversation' likely return lists but no limit/offset/pagination parameters are documented. LLMs cannot request specific result counts or handle large datasets.
IDENTITY PARAMETER AMBIGUITY: 'find_business' likely accepts name/location/phone/website per description, but no separate params for each type are documented. LLMs cannot know which value to pass or if all can be combined.