MCP servers for controlling macOS and Windows, managing calendars, Gmail, file watching, code analysis, image analysis, reminders, screen captures, and text improvement
This multi-server suite has 28 tools across 6 domain modules. While all tools have basic descriptions and most have input schemas, the quality is inconsistent. Naming follows verb-noun convention reasonably well (quick_add, list_events, delete_event, etc.), but descriptions are often too brief (10-30 chars), parameter documentation is sparse, output schemas are not documented, and error handling is minimal. Many parameters lack descriptions entirely. The critical security issues (applescript, shell tools with no sanitization hints; secrets in file paths) and lack of error recovery guidance push this into the 'fair/poor' range. For a multi-server suite managing calendar, email, files, and system control, this represents significant production gaps.
Analyze a Python file and return its structure
Load and analyze an image file
Run AppleScript command
Cancel your next meeting
Cancel a specific reminder
Delete a single event
Delete multiple events
Critical security gap: 'shell' and 'applescript' tools accept arbitrary command strings with no sanitization, injection detection, or sandboxing hints. LLMs can be prompt-injected into passing malicious payloads (e.g., `rm -rf /` embedded in user input). No validation, no confirmation step, no audit trail.
Output schemas not documented. No tool has a documented return type schema. LLMs cannot plan downstream calls, extract needed data, or validate results. E.g., 'list_events' returns what fields? IDs? Timestamps? Attendees?
Sparse parameter descriptions. Many tools have parameters with minimal or missing descriptions. E.g., 'next' has no parameters but its description doesn't explain if it returns ONE meeting or ALL upcoming meetings, or within what timeframe.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 43 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 44 | - | v1 |
Edit an existing event
Find free time slots today
Get current image analysis
Get current file analysis context
Get a specific email message
Get improvements for current text
List events for a specific date
List recent email messages
List all active reminders
List currently watched directories
Show next meeting
Send system notification
Quickly add an event
Search for emails
Send a new email
Set a reminder for X minutes from now
Set text for improvement
Run shell command
Stop watching a directory
Control system volume
Start watching a directory
Vague or missing descriptions on simple tools. 'get_context', 'list_watched', 'get_analysis' have descriptions under 20 characters or missing context. LLMs cannot determine WHEN to call these or what they return.
No error handling or recovery guidance in visible code. No error messages tell LLMs what went wrong or how to fix it. E.g., if Google Calendar auth fails, LLM gets 'auth error' with no hint to check credentials.json or retry.
Secrets and credentials exposed in file paths. Code shows 'credentials.json' and 'token.json' stored as plaintext files with hardcoded paths. If agent can call filesystem tools, it could read/exfiltrate these. Google API keys should use environment-based secret injection.
Destructive operations lack confirmation steps. 'delete_event', 'delete_events', 'cancel_next' can permanently erase calendar data with no dry-run, confirmation prompt, or undo tool. Agents can accidentally delete users' entire calendar.
No pagination or result limits documented. 'list_messages', 'search_emails', 'list_events' may return large datasets with no max result cap or next_cursor guidance in descriptions. Could blow context window.
Missing chaining fields in responses. If 'list_events' returns event summaries, does it return event_id (needed for delete_event, edit_event)? If 'search_emails' finds messages, does it return message_id (needed for get_message)? Unknown, forces extra lookup calls.
Ambiguous parameter intent in edit_event. 'start_time' and 'end_time' are ISO format strings, but description doesn't specify timezone handling, whether partial updates work, or what happens if end_time < start_time.