AI operating layer: chat + voice + second brain + automation, built on Claude Code CLI and other AI provider CLIs (Claude, ChatGPT/Codex). FastAPI application with support for multiple AI models and MCP tools.
Javis OS exposes only 1 tool: javis_read_file. The tool has a name following verb_noun convention (read_file), a brief description, and a minimal input schema with a single 'path' parameter. However, critical quality gaps emerge: the description (58 chars) lacks context about when to use it, what it returns, constraints on paths, and error handling guidance. The parameter description ('Path to the file to read') is bare-bones and provides no validation hints, format expectations, or error recovery guidance. No output schema is documented, the tool description does not specify what fields are returned or their types. Security concerns are present: the tool accepts arbitrary filesystem paths without documented restrictions, and there is no mention of sandboxing, access control, or audit logging. For a file-reading tool serving an LLM, the lack of result pagination, size limits, or content-type handling is a significant gap. The tool's risk annotation ('READ_ONLY') is present but undocumented in the tool description itself, an LLM will not know it is safe to retry.
Read a file from the filesystem. Used by Web model to access file contents.
Output schema not documented. Tool description does not specify what fields are returned, their types, or format (e.g., is it a string, JSON object, base64-encoded for binary?). LLMs cannot plan downstream operations or validate responses.
Parameter description lacks validation rules and format expectations. 'Path to the file to read' does not specify: allowed directory boundaries, symlink handling, maximum file size, supported encodings, or error cases (file not found, permission denied, is a directory). LLMs will pass invalid paths without guidance.
No error handling guidance. Tool description does not explain what happens on failure (file not found, permission denied, path traversal attempts, encoding errors) or what the LLM should do next. Error responses will not be actionable.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | F | 49 | 2026-07-28+ | v2 |
No security or access control documentation. Tool accepts arbitrary filesystem paths; description does not mention sandboxing, path validation, chroot boundaries, or which directories are readable. An LLM could be tricked into attempting path traversal (e.g., '../../../etc/passwd'). No audit trail mentioned.
No result limits or pagination. No mention of maximum file size, truncation behavior, or pagination for large files. A multi-gigabyte file could exhaust the LLM context window or cause timeouts.
Tool description too short and lacks WHAT/WHEN/WHY context. At 58 characters, the description does not explain use cases, dependencies, or when this tool should be called instead of other methods (e.g., resource URIs, prompts). LLMs may misuse it.
Risk annotation (READ_ONLY) is not exposed in the tool description or schema. LLMs will not know the operation is safe to retry. Idempotent operations should be annotated via toolAnnotations (idempotentHint) per current MCP spec.