Every public upAPI operation as an MCP tool — a local stdio server (upapi-mcp) and a handler for hosting MCP over streamable HTTP.
Four tools with mixed quality. search_ops and call_op have solid schemas and descriptions (10-50 word range, clear intent). search_tools and execute_typescript lack output schema documentation, critical for agents planning downstream calls. All tools have descriptions and input schemas, but parameter descriptions are sparse (e.g., execute_typescript's 'code' param lacks format/safety constraints in description). No error handling guidance visible. Tool composition is reasonable (discovery + execution pattern), but output structures are undocumented.
Execution: run one operation by slug.
Run a TypeScript program that calls the external_* functions search_tools declared. Batch independent calls with Promise.all instead of one round trip per operation. Killed after 30 seconds.
Discovery: search the operations THIS connection is allowed to see.
Find the upAPI operations reachable on this connection. Returns each match as a "declare function external_<name>(...)" TypeScript signature to call from execute_typescript.
Output schemas undocumented for search_tools and execute_typescript. Agents cannot plan downstream calls or extract structured data without knowing return types.
execute_typescript parameter 'code' lacks safety/format constraints in description. No mention of sandbox limits, allowed imports, or error modes. LLMs cannot reason about what code is safe to generate.
No error handling guidance visible. Tools do not document what errors are retryable, user-fixable, or fatal. Agents cannot self-correct on failure.
search_tools description mentions 'external_<name>(...) TypeScript signature' but does not explain what fields each signature contains or how to call them. Output structure is opaque.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | D | 59 | 2026-07-28+ | v2 |
call_op 'input' parameter description says 'additionalProperties: true' but does not explain what happens if extra fields are passed or how to validate against the operation's schema.