Multi-service bridge infrastructure for n8n workflows providing browser automation, file management, email operations, and Discord integration
The n8n-claw server exposes 13 tools across multiple bridges (email, file, browser, Discord). While all tools have names and most have descriptions, significant quality gaps emerge across schema definition, parameter documentation, and error handling. Tool naming generally follows verb conventions (read-emails, send-email, upload, run_task), but descriptions are inconsistent in depth and actionability. Parameter schemas are present but incomplete, many lack proper type constraints, enums for constrained values, and descriptions that would guide LLM selection. Output schemas are largely undocumented. Error handling is minimal: most tools return generic error messages without recovery guidance or actionability hints. The server mixes naming conventions (kebab-case: read-emails, send-email; snake_case: run_task, list_sessions; path-based: files/:id). Security risks are acute: email bridge accepts plaintext credentials as parameters (host, user, password, port) rather than using server-side injection. Browser bridge accepts arbitrary user_id and domain without validation. File bridge stores user-uploaded content without clear authorization checks. These patterns violate pattern:secret-injection and pattern:permission-gate fundamentally. Tool composition is reasonable, tools are narrowly scoped, but several parameters are underdocumented. For example, run_task's 'user_id' parameter lacks format guidance ("Qualified user ID (e.g. 'telegram:1810565648')") but no validation schema or error message specifies what formats are valid. The 'domain' parameter in run_task and close_session is unexplained: is it a domain regex, an exact match, or something else? File bridge lacks pagination despite storing files with TTL and presumably returning lists. Email read-emails tool returns up to a limit but no total count or next cursor, making repeated queries error-prone. Discord reply tool's automatic chunking at 2000 chars is undocumented in the schema, forcing LLMs to guess behavior.
Remove all expired files from storage and clean up metadata
Close a specific browser session for a user and domain, terminating the browser
Download a stored file as binary data with automatic decompression if gzip-encoded
Explicitly delete a stored file before expiration
Forward a stored file to an external service via HTTP (multipart or raw body), with automatic decompression
Retrieve metadata for a stored file without downloading the content
List all browser sessions for a given user with creation time, last use, and task count
Plaintext credentials exposed as tool parameters (host, user, password for email bridges)
Output schemas completely undocumented for all tools
Path-based tool naming (/:id, /meta, /forward) instead of verb-first convention
No permission checks or authorization for destructive operations
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 51 | 2026-07-28+ | v2 |
Read emails via IMAP with support for filtering by folder, date range, sender, and read status
Send a message reply through Discord bot to a specific channel, with automatic chunking for Discord's 2000 character limit
Execute a natural-language task using Browser Use agent with vision, step limit, and timeout control
Send email via SMTP with support for HTML and plain text content
Upload a file via multipart/form-data and store it temporarily with automatic expiration
Upload a file as base64-encoded JSON with optional gzip compression for storage
No error guidance or recovery suggestions in tool descriptions
Mixing naming conventions: kebab-case, snake_case, and path-based patterns
Parameter constraints missing or vague (enums, patterns, ranges not enforced in schema)
No idempotency or confirmation pattern for state-changing operations
Arbitrary URL forwarding without domain validation (files/:id/forward)
Browser bridge user_id and domain parameters lack validation and authorization