Single tool 'fetch' with minimal description and incomplete parameter documentation. Tool has a basic input schema but lacks LLM-optimized description, parameter constraints, error handling guidance, and output schema documentation. Does not follow verb_noun naming convention (should be 'fetch_website' or similar for clarity). Missing security considerations for arbitrary URL input. No pagination, rate limiting, or result constraints documented despite potential for large responses.
Fetches a website and returns its content
Tool description is too generic and lacks context. 'Fetches a website and returns its content' (47 chars) does not explain WHEN to use this tool, what formats it accepts, size limits, error handling, or potential side effects. LLMs need 50-200 char descriptions with clear selection criteria.
URL parameter lacks format specification, validation constraints, and examples. Description should state: expected format (http://, https://, file://), max length, timeout behavior, what happens for unreachable hosts, redirect limits, and any blocked domains. Currently: bare 'URL to fetch'.
No output schema documented. Tool returns list[TextContent | ImageContent | EmbeddedResource] but LLMs cannot see this contract in tool registration. Response structure, field names, size limits, and encoding should be explicit. What if response is 100MB? What if the page is binary? What fields will always be present?
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | F | 44 | 2026-07-28+ | v2 |
Security: Arbitrary URL input with no validation against SSRF, local file access, or malicious hosts. Tool accepts any URL passed by LLM without sanitization. Should document: blocked URL patterns (localhost, 127.0.0.1, 192.168.*, 10.*, file://), redirect limits, and timeout constraints to prevent resource exhaustion.
No error handling guidance in description. If fetch fails (timeout, 404, connection refused, SSL error, rate limit), LLM receives no recovery path. Should document retryability, expected error codes, and guidance like 'If URL not found, try searching for the resource first.'
No result limits or pagination documented. Tool returns response.text wholesale with no limit on response size. Large pages could exceed context window or cause timeout. Description should state: max response size accepted, truncation behavior, pagination guidance (e.g., 'returns first 10KB; for longer content, consider search tools').
Tool naming lacks clarity. Single-word 'fetch' is generic and does not follow verb_noun convention. Better names: 'fetch_webpage', 'get_webpage_content', 'fetch_website_html'. Current name conflicts with standard library functions and does not signal that it fetches *remote* content.
No User-Agent or authentication option documented. Tool hardcodes User-Agent; some sites block requests without proper headers. Should allow agent customization or document that requests will be rejected by certain servers.