MCP server for accessing iCloud services including email, calendar, reminders, and notes
iCloud MCP has 8 tools with complete JSON Schema definitions and descriptions, but quality is inconsistent. Naming follows verb_noun convention well (send_email, read_emails, create_calendar_event, etc.), meeting basic naming standards. However, descriptions are sparse (most 60-140 chars, baseline is 194 chars) and lack actionable context for LLM selection. Several parameter descriptions are missing or incomplete (e.g., list_reminders has empty properties, create_note lacks detail about limitations). Error handling is minimal, tools reference environment variables but don't document recovery paths. The most critical gap: create_note is marked 'Experimental/Not fully supported' yet is exposed as a tool, which violates the principle that tools should be reliable. Output schemas are undocumented, callers cannot know what fields to expect from read_emails, list_calendar_events, etc. No pagination support despite the likelihood of returning multiple items. Overall tool quality is below median (52 vs. production baseline ~55) due to incomplete descriptions, missing output documentation, and one broken tool in the public API.
Create a calendar event. Requires ICLOUD_EMAIL and ICLOUD_PASSWORD (app-specific).
Create a note (Experimental/Not fully supported).
Create a reminder. Requires ICLOUD_EMAIL and ICLOUD_PASSWORD (app-specific).
List calendar events. Requires ICLOUD_CALDAV_URL pointing to a specific calendar collection.
List reminders. Requires ICLOUD_REMINDERS_URL (or ICLOUD_CALDAV_URL) pointing to a reminders collection.
Read recent emails from iCloud IMAP. Requires ICLOUD_EMAIL and ICLOUD_PASSWORD (app-specific) environment variables.
create_note is marked 'Experimental/Not fully supported' yet exposed as a public tool. Handler returns isError=true. This violates tool reliability principle, agents cannot trust the tool to work.
No output schemas documented for any tool. Callers cannot know what fields to expect from read_emails, list_calendar_events, list_reminders, or read_notes. LLMs must guess what data structure is returned, causing errors in downstream reasoning and chaining.
list_reminders has empty properties ({}), no parameters documented or accepted. Description is 73 chars and does not explain what the tool returns or why to call it. Violates pattern:tool-description baseline (194 chars).
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 31 | - | v1 |
Read Notes from the 'Notes' IMAP folder. Only works for legacy notes.
Send an email using iCloud SMTP. Requires ICLOUD_EMAIL and ICLOUD_PASSWORD (app-specific) environment variables.
Descriptions are consistently short (50-73 chars for most tools, 20 chars for create_note). Baseline for production tools is 194 chars. Missing context on WHEN to use each tool, what it returns, and dependencies (e.g., 'Requires ICLOUD_CALDAV_URL' mentioned in some but not all).
No pagination support for list_* and read_* tools. Tools accepting 'limit' parameter but no offset/cursor or total_count in output. If email or calendar contains 1000+ items, agents cannot page through results, will hit context limits or miss data.
Environment variable dependencies (ICLOUD_EMAIL, ICLOUD_PASSWORD, ICLOUD_CALDAV_URL, ICLOUD_REMINDERS_URL) are documented in descriptions but there is no validation or error guidance. If variables are missing, tools will fail with unhelpful error messages instead of guiding the user to set them.
Credentials (ICLOUD_EMAIL, ICLOUD_PASSWORD app-specific) are passed via environment variables but described in tool descriptions. Descriptions should not mention credentials, rely on silent server-side injection. Publishing credential requirements in descriptions educates attackers on what to target.
create_note description mentions '(Experimental/Not fully supported)' but does not state what the limitation is or how to work around it. Handler code shows it returns an error message instead of creating. Users and agents will attempt to use it and hit confusing errors.
read_notes description states 'Only works for legacy notes'. No explanation of what 'legacy notes' means or how modern notes differ. LLMs cannot determine whether to call this tool without knowing the scope of what 'legacy' includes.