An Azure Functions-based MCP server exposing restaurant directory operations (search, menu retrieval, order placement) via HTTP transport. Demonstrates dual-door architecture: same backend exposed as both REST API and MCP tools.
Three tools with clear verb-noun naming (search_restaurants, get_menu, place_order) and solid descriptions (avg 95 chars, all 50+ chars). Input schemas present with proper JSON Schema structure and type definitions. All parameters have descriptions. However, output schemas are undocumented (tools return JSON strings with no declared structure), and error handling lacks recovery guidance. Missing parameter constraints (e.g., quantity 1-20 stated in description but not in schema as minItems/maxItems). No tool annotations (readOnlyHint/destructiveHint) despite clear risk profiles.
Gets the menu for one restaurant, including item names, descriptions, and prices in euros.
Places an order for one menu item at a restaurant and returns a confirmation with the total price.
Searches the restaurant directory. Both filters are optional; call it without arguments to list every restaurant.
Output schemas undocumented. Tools return JSON strings but no schema declares the structure of results (e.g., restaurant object fields, menu item fields, order confirmation fields). LLMs cannot plan downstream operations or extract specific fields without guessing.
Parameter constraints not formalized in schema. 'quantity' description states '1-20' but schema lacks minItems/maxItems. 'cuisine' and 'city' are free-form strings with no enum or pattern. LLMs may pass invalid values; validation happens server-side only.
Error responses lack recovery guidance. 'No restaurants matched' and 'Restaurant not found' tell the LLM what failed but not what to do next. Should suggest 'Try a different cuisine' or 'Use search_restaurants first to get a valid id', which is present in code but not in structured error format.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 79 | 2026-07-28+ | v2 |
Tool annotations missing. place_order is destructive (WRITE risk) but schema has no destructiveHint. search_restaurants and get_menu are read-only but lack readOnlyHint. Annotations enable agents to reason about safety and retry logic.
No pagination support. search_restaurants returns all matching results without limit or offset. If restaurant directory grows large, response could exhaust context window. Should add optional limit and offset parameters.