An MCP server for sending and retrieving emails via Gmail using SMTP and IMAP protocols
Two tools with basic implementations but significant gaps in description quality, schema completeness, and error handling. send_email has a reasonable description (74 chars) and moderate schema coverage, but list_recent_emails lacks proper input parameter documentation and both tools expose environment variable injection risks. Neither tool includes error recovery guidance, output schemas are undocumented, and parameter constraints are missing. The tools follow basic verb_noun naming but fall short of production-grade quality standards.
List recent emails from the inbox.
Send an email using SMTP.
list_recent_emails has no description for the 'limit' parameter. The parameter is documented in the tool description but the parameter annotation is missing, forcing LLMs to infer its meaning and valid range.
No output schemas documented for either tool. Callers do not know what structure send_email or list_recent_emails returns. send_email returns a bare string; list_recent_emails returns newline-delimited preview text. Without structured output, downstream tools cannot reliably parse results.
Error responses do not guide recovery. send_email returns strings like 'Error: Authentication failed' with no hint about what to do next (e.g., 'Check EMAIL_ADDRESS and EMAIL_PASSWORD in your .env'). list_recent_emails has no error handling visible and will crash on missing credentials.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 44 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 41 | - | v1 |
Credentials (EMAIL_ADDRESS, EMAIL_PASSWORD) are loaded from environment variables and used inside tools. While this avoids exposing them as parameters, the implementation offers no audit logging, permission gating, or rate limiting. If an agent calls send_email repeatedly, there is no protection against mail-bombing or credential misuse.
send_email lacks input validation constraints in the schema. The description says 'recipient_email' is required but does not specify acceptable format, length limits, or examples. The body parameter has no character limit, encoding specification, or guidance on HTML vs plain text. LLMs may pass absurdly long bodies or invalid addresses.
list_recent_emails has a default limit of 5 emails but does not document this in the parameter description. The code shows 'limit=5' but the schema description only says 'Maximum number of recent emails to retrieve (default: 5)', contradicting the LLM-facing schema which should explicitly state the default value in minItems/maxItems or the description text.
send_email description does not mention side effects or idempotency. Agents do not know whether retrying the same call will send the email twice or safely return 'already sent'. This is critical for agent error recovery.
No pagination support in list_recent_emails. If a user has thousands of emails, the tool will attempt to fetch and process all of them, risking timeout, memory exhaustion, and context window overflow. The limit parameter is present but there is no offset, cursor, or next_token to enable pagination.