MCP server for sending emails via Lemon Email API. Provides direct integration with Lemon Email transactional email service for AI agents and applications.
Single tool 'send_email' has a proper verb-noun name and comprehensive schema definition. However, the description in the actual tool registration (from list_tools()) differs significantly from the sampled version shown in the evaluation request. The schema visible in code includes proper types, descriptions, and defaults for all parameters. Critical issue: API key is exposed as a required parameter in the actual implementation shown in chatgpt_mcp_server.py (api_key field in inputSchema), which violates the secret-injection pattern. The description acknowledges stateless operation and no server-side storage, but the implementation contradicts this by requiring the user to provide the API key per-request as a parameter. This is a security anti-pattern. Parameter descriptions are generally good (80-150 chars), but the tool lacks output schema documentation and error handling guidance. The server claims 'no API key stored server-side' but forces the user to pass it as a tool parameter, which will be logged in agent traces.
Send an email directly via Lemon Email API. Perfect for AI agents to send transactional emails, notifications, and messages.
API key exposed as tool parameter despite security documentation claiming it is 'NOT stored on the server.' Credentials in tool parameters are logged in agent traces and prompt history, violating secret-injection pattern.
Output schema not documented. Tool returns dictionary with 'success', 'status_code', 'response', and potentially 'error' fields, but the schema is not declared to the LLM. LLMs cannot infer downstream data extraction or error detection.
No error recovery guidance. When API returns failure (e.g., 401 Unauthorized, 422 Unprocessable Entity), the error response does not suggest remediation steps. LLM receives raw error text without actionable next steps.
Parameters 'fromname' and 'toname' have empty string defaults, but descriptions do not explain the consequence of omission or when they are required for proper email formatting.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 66 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 47 | - | v1 |
Description in sampled evaluation request differs from actual chatgpt_mcp_server.py implementation. Evaluation request shows fromname and fromemail in defaults, but code shows api_key as a required parameter not present in the sampled schema. Mismatch suggests incomplete code submission or evolving API contract.