MCP server for Gmail API with OAuth2 authentication and comprehensive email management
Strong foundation with comprehensive tool coverage and well-structured schemas. All 20 tools have clear descriptions (average 80-120 chars) and complete input schemas with Zod validation. Parameter descriptions are consistently present and detailed. However, output schemas are not documented, responses are inferred from implementation rather than explicitly specified in tool definitions. Error handling is basic; some tools lack recovery guidance. Security considerations around attachment handling and filter creation need strengthening. Overall follows the chat-data-model pattern reasonably well with verb-first naming, but could benefit from richer composition patterns and explicit output documentation.
Permanently deletes multiple emails in batches
Modifies labels for multiple emails in batches
Gets exact email count for a label using Gmail API label metadata (provides total and unread counts)
Creates a new Gmail filter with custom criteria and actions
Creates a filter using a pre-defined template for common scenarios
Creates a new Gmail label
Output schemas not documented in tool definitions. Responses inferred from implementation code; LLMs cannot reason about what fields to expect from each tool call.
No explicit error handling guidance. Tools lack recovery suggestions when operations fail (e.g., 'If email not found, try search_emails first'). Error responses are system errors rather than actionable guidance.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 76 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 41 | - | v1 |
Permanently deletes an email
Deletes a Gmail filter
Deletes a Gmail label
Downloads an email attachment to a specified location
Draft a new email
Gets details of a specific Gmail filter
Gets an existing label by name or creates it if it doesn't exist
Retrieves all available Gmail labels
Retrieves all Gmail filters
Modifies email labels (move to different folders)
Retrieves the content of a specific email
Searches for emails using Gmail search syntax
Sends a new email
Updates an existing Gmail label
No confirmation or dry-run pattern for destructive operations. delete_email, batch_delete_emails, delete_label, delete_filter perform irreversible actions without opportunity to confirm. Agents cannot prevent accidental data loss.
Attachment handling (download_attachment, send_email attachments) lacks security guidance. No validation of file paths, MIME types, or size limits documented. Risk of directory traversal or exfiltration.
create_filter and create_filter_from_template lack input validation constraints. Criteria object properties (query, negatedQuery, subject) are unvalidated free-form strings; could accept malformed Gmail queries. Email address fields (from, to, forward) should be constrained with format: email.
search_emails maxResults parameter defaults to 10 and caps at 500, but no pagination cursor or total count returned. Large result sets may exceed context window without guidance on how to fetch next page.
Tool names could be more granular. 'modify_email' is ambiguous, does it rename, mark as important, update labels? Related: batch_modify_emails. Consider separate tools: add_email_labels, remove_email_labels for clarity.
list_email_labels and list_filters have no output limits documented. If user has 500+ custom labels or filters, response bloats context window. Should cap at reasonable limit (20-50) and offer pagination.
count_emails requires either labelId OR labelName, but description doesn't clearly explain resolution logic when labelName is provided (how is it looked up?). Dependency between parameters not fully documented.
Tool descriptions could include hints about when to use each one. E.g., draft_email vs send_email, when should agent choose draft over send? Current descriptions are identical except verb.