An MCP server that sends automated emails with resume attachment via Gmail
Single tool 'send_email' with functional but minimal quality. Tool name follows verb_noun pattern correctly (send_email). Description is present but very short (59 chars), below ideal 50-200 char range. Input schema is complete with proper JSON Schema structure and all params typed as strings. However, critical gaps in parameter descriptions (none exceed 30 chars), no output schema documented, and parameter descriptions lack actionable constraints. No error handling guidance, errors are logged to stderr but not surfaced with recovery hints to the LLM. Tool is high-risk (WRITE/destructive) but lacks confirmation pattern. Security issue: GMAIL_USER exposed in process.stderr logs and error messages, violating secret-injection pattern.
Send an email on behalf of the user, always attaches resume
Tool description is too short (59 chars) to guide LLM on when to use vs alternatives or expected side effects. Lacks actionable context about state mutation.
Parameter descriptions are extremely brief (7-28 chars). 'Recipient email address' lacks format validation hint. 'Subject line' and 'Email body' provide no constraints on length, encoding, or special characters. LLM has no guidance on valid input boundaries.
No output schema documented. LLM does not know what fields to expect from send_email response (e.g., message_id format, timestamp, recipient confirmation). This breaks downstream tool composition and planning.
Destructive tool (sends email) has no confirmation pattern or dry-run mode. Agents may accidentally send emails to wrong recipients. No idempotent/destructive hint in annotations.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 45 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 34 | - | v1 |
Error handling returns raw error messages to LLM without recovery guidance. E.g., 'Failed to send email Error: ...' does not tell agent: retry? Ask user? Is it fatal? No actionable next steps.
Security: GMAIL_USER (credential) is logged to stderr in error responses ('Failed to send email Error: ...'). If agent logs or traces stderr, credential leaks. Tool response also echoes GMAIL_USER in success message, violating secret-injection pattern.
Tool always attaches resume (description says 'always attaches resume') but resume path optional at runtime (warns if RESUME_PATH unset). This creates expectation mismatch: LLM thinks resume always attached, but it may not be. Description is misleading.
No 'to' parameter validation. Does not check email format (RFC 5322). LLM may pass malformed addresses; tool silently fails or passes invalid input to nodemailer. No constraint hint in parameter description.
Missing 'subject' and 'body' length constraints. LLM could pass empty strings or gigabyte-sized payloads. No guidance in descriptions.