An MCP server for document review and analysis with interactive UI support, file management, web search, and AI-powered document processing using Google Generative AI.
This server has 5 tools with significant quality gaps. Tool naming follows action-verb conventions (select_, get_, save_, _log, _run_web_search_impl), which is positive. However, descriptions range from adequate to vague, parameter schemas are present but lack rigor, and critical error handling is absent. The '_log' and '_run_web_search_impl' tools expose internal implementation details and lack user-facing value. Output schemas are not documented. Most critically, the server lacks structured error responses that guide the LLM on recovery, and does not validate inputs before processing. The average tool score across the 5 tools is 42/100.
Bridges standard logging to MCP protocol logging.
Internal implementation of web search with optional MCP context. Using AsyncClient to avoid blocking the event loop.
Reads a file and returns a UIResource containing the interactive viewer HTML.
Saves the provided content to the specified file.
List text-based files in the given directory or return the file itself if a file path is provided. If no path is provided, starts at the project 'docs' directory. Returns a list of absolute file paths.
Internal implementation tools (_log, _run_web_search_impl) exposed as public tools, violating pattern:tool principle of single, user-facing responsibility. Tool names with underscore prefix and '_impl' suffix signal internal detail, not user action.
No structured error responses or recovery guidance. Errors are raw strings or error objects without actionable next steps for the LLM. E.g., 'Error: Path not found: /some/path' tells LLM nothing about how to recover.
No input validation or parameter constraints documented. Parameters like 'path' and 'filepath' lack format specifications (absolute vs relative? symlink resolution? max length?). LLM cannot validate inputs before passing them.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | F | 43 | <=2025-11-25 | v2 |
Destructive tool (save_file) lacks dry-run, confirmation, or undo mechanism. Pattern:confirmation-request recommends confirmation step for irreversible operations. Agent could overwrite critical files without warning.
Output schemas not documented. Tools return data structures (List[str], List[UIResource], str) but LLM has no schema to understand response fields, structure, or pagination. Violates pattern:tool requirement for documented output.
Tool descriptions lack context on when to use each tool vs alternatives. E.g., select_file vs get_document_ui distinction is unclear. LLM may select the wrong tool.
Path traversal vulnerability: select_file and get_document_ui accept file paths without validating they remain within project boundaries. LLM could be tricked into reading /etc/passwd or other sensitive files via prompt injection.
Web search tool (_run_web_search_impl) requires external API keys (LANGSEARCH_API_KEY) but does not document this in description or validate they exist before LLM calls it. Failure leaves LLM with no recovery path.
No permission checks or scope declarations. Any agent with access to these tools can read any file in the docs directory or write to it without authentication/authorization. Missing pattern:scope-declaration and pattern:permission-gate.