MCP server for creating Gmail drafts with recipient, subject, and body
Single tool with minimal definition quality. Tool name follows verb_noun convention correctly ('write_email_draft'), but description is extremely sparse at 56 characters. Input schema is fully present with proper types and field descriptions, but output schema is completely undocumented. No error handling guidance, no security considerations for credential management, and no documentation of side effects. The tool modifies state (creates Gmail draft) but this critical fact is buried in the description rather than explicitly stated. Tool exhibits high-risk WRITE operations without confirmation or dry-run capability.
Create a Gmail draft using recipient, subject, and body.
Sparse tool description (56 chars) lacks context for agent selection and lacks explicit statement of side effects. Missing: when to use this tool, what it returns, error recovery guidance.
Output schema completely undocumented. LLM cannot infer what fields are returned or plan downstream tool calls. Expected: document that the response contains 'id', 'message', 'threadId', and 'error' fields with types.
Credentials (GOOGLE_TOKEN_PATH, GOOGLE_CREDENTIALS_PATH, USER_EMAIL) are managed via environment variables in implementation, but the tool parameter descriptions and security documentation do not address how credentials are handled. No explicit statement that secrets are injected server-side.
Destructive/irreversible operation (creates Gmail draft, modifies user email state) lacks confirmation step or dry-run capability. Agents may accidentally create unwanted drafts on retry loops.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 47 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 43 | - | v1 |
Error handling in implementation (gmail.py) returns {'error': str(error)} on HttpError, but no guidance is provided to the LLM about what to do next, whether to retry, or how to self-correct. Error responses lack actionable recovery steps.
No parameter validation or constraint documentation. 'recipient_email' accepts free-form strings with no format validation, pattern, or constraint documented. Invalid email addresses may silently fail at Gmail API layer.
No tool scope or permission declaration. The tool claims 'gmail.compose' scope but this is not documented in the tool definition, making it unclear to agents and users what permissions this tool requires.