Model Context Protocol server for Microsoft Outlook mail (Microsoft Graph) — read, search, draft, send, reply, forward and organize email plus manage OneDrive files, with browser sign-in and safe-by-default access modes and guards.
MCP Outlook demonstrates solid definition quality with 21 well-named tools, comprehensive descriptions, and properly typed schemas. Naming conventions are strong (verb_noun pattern consistently applied: list_*, get_*, create_*, search_*, send_*, delete_*, mark_*, move_, upload_). Descriptions are detailed and actionable, averaging ~150 chars and explaining WHAT each tool does, WHEN to use it, and any prerequisites. All parameters have type definitions and descriptions. However, output schemas are not explicitly documented in the provided code, limiting visibility into return structures. Error handling is present (toErrorResult function shows contextualized errors with AUTH and POLICY classification) but lacks explicit recovery guidance in tool descriptions. Tool composition is excellent, single-responsibility principle followed, with clear tool chains (e.g., list_messages → get_message → reply_message). Security model is well-designed with server-side credential injection, policy-based access control (SecurityPolicy), and confirmation prompts for destructive operations. No sensitive parameters exposed. Baseline comparison: naming matches production standards (18 char avg); descriptions well above 10 - 1024 range; all params typed and described.
Create a draft message (not sent). Specify subject, body, and recipients (to/cc/bcc). Returns the draft's id for later send/reply/forward.
Delete a OneDrive file or folder by id. It goes to the OneDrive recycle bin (recoverable), not a permanent purge. Requires admin mode and OUTLOOK_ALLOW_DELETE=true, and prompts for human confirmation.
Delete a message by id. It is moved to the Deleted Items folder (recoverable from there), not permanently purged. Requires admin mode and OUTLOOK_ALLOW_DELETE=true, and prompts for human confirmation.
Download a OneDrive file's contents as text (capped at ~1 MB). Best for text/markdown/JSON/CSV; binary files come back as best-effort UTF-8, so prefer webUrl for those. Give `path` or `item_id`.
Forward a message to new recipients. Optionally include a comment. Requires OUTLOOK_ALLOW_SEND=true.
Output schemas not explicitly documented in code. While input schemas are well-defined with proper types and descriptions, return value structures are inferred from descriptions rather than formally declared. This limits LLM ability to programmatically understand response shapes for composition.
No explicit recovery guidance in error messages returned to LLM. While toErrorResult() categorizes errors (PolicyError, AuthError, GraphError), the error responses do not include actionable next steps like 'Try using search_messages() first' or 'Check OUTLOOK_ALLOW_SEND=true'.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 66 | 2026-07-28+ | v2 |
Fetch metadata for a single OneDrive file or folder by `path` or `item_id`.
Fetch a single message by id with its full body, recipients (to/cc/bcc), importance, and conversation id. Get ids from list_messages or search_messages.
List a message's attachments as metadata only (id, name, contentType, size, isInline). Attachment bytes are intentionally not returned.
List the mailbox's personal contacts (display name, email addresses, company).
List the files and folders in a OneDrive folder. Give a `path` relative to the drive root (e.g. "/Documents"), or an `item_id` from a previous result. Omit both for the root. Returns id, name, isFolder, size, childCount, lastModified, webUrl.
List the mailbox's top-level mail folders with their ids, display names, and unread/total counts. Use a folder id or well-known name (inbox, sentitems, drafts, archive) with list_messages.
List messages, most recent first. Optionally scope to a folder and/or only unread messages. Returns compact summaries (id, subject, from, received, isRead, hasAttachments, preview). Fetch full bodies with get_message.
Mark a message as read or unread.
Move a message to a folder (copy, then delete from source).
Reply to a message to all recipients. Optionally include a comment/message. Requires OUTLOOK_ALLOW_SEND=true.
Reply to a message (to sender only). Optionally include a comment/message. Requires OUTLOOK_ALLOW_SEND=true.
Search across OneDrive for files and folders matching a query (name/content).
Full-text search across the mailbox (subject, body, sender, recipients) using Microsoft Graph $search. Example queries: "invoice", "from:alice@contoso.com", "subject:release". Returns compact summaries.
Send a message immediately. Specify subject, body, and recipients (to/cc/bcc). Requires OUTLOOK_ALLOW_SEND=true.
Upload a text file to OneDrive at the given path. If the file exists, it is overwritten. Returns the item id and webUrl.
Return the signed-in mailbox's identity (display name, user principal name, id). Use this to confirm which mailbox the server is operating on before reading or writing.
Pagination parameters (top/limit) not consistently capped with minimum/maximum documentation. list_messages, search_messages, list_contacts, search_drive_files accept 'top' parameter but descriptions do not explicitly state the OUTLOOK_MAX_RESULTS cap value or recommend a reasonable default range (e.g., 1-100).
Mutually exclusive parameters not documented. list_drive_items accepts both 'path' and 'item_id'; get_drive_item accepts both 'path' and 'item_id'. Descriptions should state 'Provide EITHER path OR item_id, not both' to prevent LLM confusion.
Natural-language identifiers not mentioned. Folder parameters accept 'folder id or well-known name (inbox, sentitems, drafts, archive)' but other string params (e.g., move_message destination_folder) only mention 'folder id'. LLM may not know to try friendly names.