MCP server providing programmatic access to Apple Mail on macOS
This MCP server has 14 well-named tools with consistent verb-noun patterns (list_, search_, get_, send_, mark_, move_, flag_, create_, delete_, reply_, forward_). Input schemas are present and mostly complete with type definitions and descriptions. However, output schemas are entirely absent from the code provided, the tool creators return structured objects but no formal output schema documentation is visible. Descriptions are present but generic (avg ~60 chars), lacking LLM-optimized context about WHEN to use each tool or how they chain together. Parameters have types and descriptions, but some lack enum constraints (e.g., 'color' enum in flag_message is present but several tools accept free-form strings). Error handling exists (security/OperationLogger) but recovery guidance is not visible in tool definitions. Security is a strength, the logger is threaded through every operation, and no secrets appear in parameters. Overall, this is a solid but incomplete implementation: good naming and basic structure, but missing output documentation and richer descriptions.
Create a new mailbox/folder
Delete messages (move to trash or permanently delete)
Set color flag on messages
Forward a message
List attachments from a message
Get full details of a specific message
List all mailboxes for an account
Output schemas missing entirely. No formal documentation of what fields each tool returns. LLMs cannot plan downstream tool calls or extract required data without knowing the response structure.
Tool descriptions are generic and under-optimized for LLM discovery. Most are single-line statements (avg ~50 chars). Descriptions lack context about WHEN to use each tool, dependencies (e.g., 'search_messages first to get message_id'), or what makes this tool distinct from similar tools.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 64 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 21 | 2024-11-05+ | v1 |
Mark messages as read or unread
Move messages between mailboxes
Reply to a message
Save attachments to disk
Search for messages matching criteria
Send an email via Apple Mail
Send an email with file attachments
Missing error handling documentation. No guidance in tool definitions about how to recover from common failures (e.g., 'message not found', 'invalid recipient', 'quota exceeded'). Recovery guidance must be embedded in error responses or tool descriptions.
Parameter descriptions lack format and constraint details. E.g., 'limit' parameter has min=1 max=1000 in schema but this is not stated in the description text. LLMs cannot read JSON Schema constraints, they rely on description text. Similarly, 'color' enum values are present but not enumerated in the description.
Potential for destructive operations without dry-run or confirmation. delete_messages with permanent=true flag irreversibly deletes messages, but there is no confirmation mechanism or dry-run step to prevent agent mistakes.
Tool-chaining clarity missing. send_email_with_attachments requires file paths, but save_attachments returns a directory; unclear if paths returned by save_attachments are compatible with send_email_with_attachments expectations.