MCP server exposing beam (ephemeral text transport) as tools for AI agents.
Three well-named tools with clear, action-oriented names (beam_send, beam_get, beam_info). All tools have descriptions (194 - 250 chars, within baseline 34 - 392 range). Input schemas are present and use Zod validation with type constraints (min/max, integer flags). However, output schemas are not documented, responses are returned as JSON strings without field-level documentation. Parameter descriptions are present but minimal (avg ~60 chars vs baseline 72). No error recovery guidance or actionable error messages visible in the code. Risk annotations (WRITE, DESTRUCTIVE, READ_ONLY) are declared but not exposed as tool annotations in the MCP schema.
Retrieve a beam by id. This CONSUMES a view — the beam's text is deleted once its view count or TTL runs out, so only call this when you actually intend to read it now.
Check whether a beam still exists (and its remaining views/expiry) WITHOUT consuming a view. Use this to check status before deciding whether to fetch it with beam_get.
Send text through beam and get back a one-time (or view-limited) link. Use this instead of printing secrets, tokens, or long output inline when handing something off to a human or another agent.
Output schemas not documented. Tool responses return JSON strings without field-level documentation. LLMs cannot infer what fields to expect (e.g., does beam_send return {url, id, expiresAt}? Does beam_info return {views_remaining, ttl_remaining}?). This forces LLMs to guess field names for downstream operations.
No error recovery guidance. The toolError() function is called on exceptions, but the code does not show what error messages are returned or whether they guide the LLM on next steps (e.g., 'Beam expired. Try beam_info() first to check status'). Agents cannot self-correct.
Risk annotations (WRITE, DESTRUCTIVE, READ_ONLY) declared in comments but not exposed as MCP tool annotations. The schema does not include readOnlyHint, destructiveHint, or idempotentHint fields. LLMs cannot see which tools have side effects.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | A | 83 | 2026-07-28+ | v2 |
Parameter descriptions are minimal. 'The beam id (from a beam URL)' lacks format guidance (is it alphanumeric? length constraints?). 'Views allowed before it self-destructs' does not explain what happens when views=0 or if the default is truly 1.
No confirmation or dry-run pattern for beam_send (WRITE operation). Agents can accidentally send sensitive data without a chance to review. Consider adding a 'preview' mode or requiring explicit confirmation.