MCP server with 22 tools for email, calendar, contacts, and settings via Microsoft Graph API
Strong definition quality with clear naming conventions, mostly comprehensive schemas, and good parameter descriptions. However, several tools lack output schema documentation, and some parameter descriptions could be more explicit about constraints and valid ranges. All 8 tools have names that start with action verbs and are appropriately scoped. Schema completeness is high (all tools have input schemas with types), but output shapes are not formally documented in the provided source. Error handling descriptions are present but vary in specificity.
About tool handler — returns server diagnostics including version, tool count, timezone, test mode, rate limit, recipient allowlist, and scopes.
Access shared mailbox handler. Requires Mail.Read.Shared permission. Returns email messages from a shared mailbox folder with support for verbosity levels (minimal, standard, full).
Authentication tool handler — supports browser redirect and device code flow. Returns authentication instructions or status.
Clear message flag handler. Removes flags from one or more messages with optional mark-as-complete action.
Create a new calendar event on the signed-in user's default calendar. Returns the created event with its `id`, `webLink`, and (if attendees are present) an auto-generated online-meeting URL — attendees receive invitations on save. Times use the configured timezone (default Australia/Melbourne; override with `OUTLOOK_DEFAULT_TIMEZONE`); omit the `Z` suffix to send local time. Use `manage-event` action=`update` to modify an event after creation, or `manage-event` action=`cancel`/`delete` to remove it.
Output schemas not formally documented. While input schemas are present and well-typed, the tools lack explicit documentation of return value structures (fields, types, field meanings). This forces LLMs to infer output shapes from context.
access-shared-mailbox naming is ambiguous. 'Access' is a weak verb; the tool retrieves messages. Better name: 'list-shared-mailbox-messages' or 'get-shared-mailbox-messages'. Current name does not clearly signal the action.
Parameter descriptions for set-message-flag and clear-message-flag lack clarity about required combinations. Both accept either single messageId OR array of messageIds, but descriptions do not explicitly state this is a choice (mutually exclusive vs optional). Ambiguous dependencies.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 69 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 57 | 2024-11-05+ | v1 |
List upcoming calendar events for the signed-in user (read-only). Returns an array of events with id, subject, start/end, attendees, location, organiser, and webLink. Use `count` (default 10, max 50) to control page size; this tool does not filter — use the Outlook UI or specific date ranges via Graph for filtered queries. Each start/end is returned as a canonical UTC ISO-8601 instant (e.g. `2026-04-02T22:00:00.000Z`) followed by a labelled local rendering in the configured display timezone (default Australia/Melbourne; override with `OUTLOOK_DEFAULT_TIMEZONE`) — the UTC value is authoritative, so consumers never have to guess the zone.
Manage an existing calendar event (destructive: covers update/decline/cancel/delete — use dryRun where supported to preview). action=`update` edits fields in place via PATCH (subject, start, end, attendees, body, location, isOnlineMeeting, sensitivity, showAs, importance, categories, reminderMinutesBeforeStart) — only fields you pass are changed; pass `dryRun: true` to preview the PATCH payload. action=`decline` declines an invitation (optional `comment`). action=`cancel` cancels an event you organised and notifies attendees. action=`delete` permanently removes the event. Returns the updated event on update; status confirmation otherwise. Note: there is no `accept` action — accept invitations in the Outlook UI (Graph's accept verb is unreliable across personal/M365).
Set message flag handler. Flags one or more messages for follow-up with optional due date and start date. Supports both single message ID and array of IDs.
manage-event accepts both 'eventId' and 'id' as aliases for the same field (documented as 'v3.7.3 alias pass'). While pragmatic for backwards compatibility, this creates cognitive overhead for LLMs deciding which parameter to use. Prefer a single canonical name with a deprecation note.
set-message-flag and clear-message-flag have no required parameters; both messageId and messageIds are optional. This allows invalid calls with neither parameter. At least one should be required.
manage-event 'start' and 'end' parameters accept oneOf [string | object], complicating input parsing. Description mentions two formats but does not clarify when to use each (string vs {dateTime, timeZone} object). Guidance is fuzzy.