An MCP server that exposes Form.io forms and submissions as tools for AI agents, enabling agentic form automation and data collection workflows.
Form.io UAG provides 10 tools with reasonable naming and explicit input schemas. Tool names follow verb_noun conventions (get_forms, submit_completed_form, etc.) and are action-oriented. However, descriptions vary significantly in quality and depth. Several tools have minimal descriptions (under 50 characters), and output schemas are not documented in the visible code. Error handling guidance is absent from tool definitions. The server demonstrates mid-tier quality: basic schema coverage but incomplete descriptions and missing recovery patterns.
Agent command to provide data to a form through the agentic workflow.
Record field data being collected from the user as the conversation progresses.
Confirm the collected form data before final submission, showing a summary to the user.
Fetch external data from configured data sources or APIs for use in form population.
Find a submission in a form by submission ID or other criteria.
Get detailed information about a specific field in a form, including type, validation rules, and allowed values.
Get the fields for a specific form.
Output schemas not documented. Tools return results but there is no visible JSON Schema or structured description of return types (e.g., what fields are in the response for get_forms or get_field_info). LLMs cannot plan downstream tool calls without knowing return structure.
Minimal tool descriptions lack context for LLM selection. 'Get a list of forms that the user has access to submit' (get_forms) and 'Confirm the collected form data before final submission' (confirm_form_submission) are vague about when to call versus similar tools. No guidance on prerequisites or dependencies.
No error handling guidance in tool definitions. Tools lack descriptions of failure modes, recovery steps, or actionable error messages. An LLM encountering 'form not found' has no guidance on whether to retry, call get_forms first, or ask the user.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 65 | <=2025-11-25 | v2 |
Get a list of forms that the user has access to submit.
Update an existing form submission with new data.
Submit a completed form to Form.io after user confirmation.
Write operations lack confirmation/dry-run support. submit_completed_form and submission_update are destructive but have no dry-run or confirmation step. Agents can irreversibly submit forms or overwrite data without explicit user approval.
Parameter 'data' (in collect_field_data, agent_provide_data, submission_update) is an unconstrained object. No schema enforces field names or types. LLMs can pass arbitrary data; the tool must validate server-side and return actionable errors.
No pagination guidance. get_forms and get_field_info may return large result sets. No visible limit parameter, offset/page parameter, or total count in responses. Large unbound results blow context window.
Missing permission/scope declarations. Tools like submit_completed_form and find_submission do not state what permissions they require (read:forms, write:submissions, etc.). Unclear who can call what.