An MCP server to interact with iMessage and Contacts
This server has moderate gaps in definition quality. Both tools have clear, verb-based names (send_imessage, search_contacts) and basic schemas are present. However, parameter descriptions are minimal (1-2 words), output schemas are completely undocumented, and error handling lacks recovery guidance. The tool descriptions are brief but adequate. Missing: per-parameter validation rules, output structure documentation, error classification, and actionable error messages. The AppleScript injection risk (unescaped query in search_contacts) compounds security concerns.
Search contacts by name, phone, or email
Send an iMessage using Messages app
Output schemas completely undocumented. Both tools return content as unstructured text (raw JSON or plain text), but the LLM has no schema to parse the response structure, field names, or types. LLMs cannot plan downstream operations or extract data reliably.
Parameter descriptions are inadequate. 'Phone number or email of the recipient' and 'Search query' are too terse. No format guidance (e.g., E.164 for phone, partial name matching for query), no constraints (length, regex pattern), no examples. Violates baseline: 100% of A+ tools have descriptive param annotations (avg 72 chars).
Error handling does not guide recovery. Both tools return raw exception messages on failure (e.g., 'AppleScript error: ...'). LLM cannot determine if error is retryable, what user action is needed, or how to proceed. Violates pattern: errors must tell LLM what to do next.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 32 | - | v1 |
No input validation or sanitization. search_contacts passes the query string directly into AppleScript without escaping: `if ((name of p as text) contains "${query}")`. An attacker or confused LLM could pass `"); return "evil` to break the script or cause injection. send_imessage does escape the message string (line: `message.replace(/"/g, '\\"')`), but search_contacts does not.
Tool descriptions lack key context. send_imessage does not state that it modifies state (send is irreversible), what success looks like, or when to use it vs alternatives. search_contacts does not explain search behavior (exact match? substring? case-sensitive?). Violates baseline: descriptions must answer WHAT, WHEN, and what it returns.
No permission or scope declaration. Tools interact with Messages and Contacts apps on the user's device, which requires implicit permission/security context. No documentation of what permissions or access levels the agent needs. Violates pattern: each tool should declare what permissions it requires.