Gmail MCP server for Claude CLI — API (OAuth) and SMTP/IMAP backends
The server provides 3 tools with reasonable names (send_email, search_emails, read_email) that follow verb_noun conventions. Descriptions are present for all tools and most parameters, but they lack detail about constraints, error cases, and output structure. Schemas are properly typed in the source but lack explicit output documentation. Error handling is minimal, tools return generic strings instead of structured error messages with recovery guidance. No tool annotations (readOnlyHint/destructiveHint) are present. The send_email tool lacks critical security guidance (no mention of attachment path validation or potential injection vectors). Parameter descriptions are present but sparse, no mention of valid email formats, limits on attachment sizes, or what happens when attachments fail to read.
Fetch the full content of an email by its UID (from search_emails results). Args: uid: Email UID shown in search_emails output
Search Gmail using full Gmail search syntax (from:, subject:, is:unread, etc). Pass a single query string for a flat list of results, or a list of queries to run several searches in one call (output is sectioned by query, and max_results applies per query). Returns UID, sender, subject, date, and a Gmail web URL for each match. Args: queries: Single query string or list of query strings. max_results: Max emails to return per query (default 10).
Send an email via Gmail. Args: to: Recipient email address(es). subject: Email subject line. body: Email body content (plain text or HTML). cc: CC recipient(s), optional. bcc: BCC recipient(s), optional. html: If True, send body as HTML instead of plain text. attachments: List of local file paths to attach, optional. Files that cannot be read are skipped with a warning.
Missing output schema documentation. Tools return unstructured strings instead of documented structured objects. Agents cannot plan downstream operations or extract data reliably.
No error guidance or recovery hints. All error conditions return generic strings like '_NO_BACKEND_MSG' with no actionable next steps. Agents cannot self-correct.
Missing tool annotations. send_email is destructive but has no destructiveHint annotation. search_emails and read_email are read-only but lack readOnlyHint annotation. Agents cannot distinguish safe from risky operations.
search_emails lacks pagination support. No limit enforcement in code, no next_cursor or offset/page parameters, no statement of max results in responses. Returning all results for a broad query could blow context window.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | D | 57 | 2026-07-28+ | v2 |
Parameter descriptions lack critical constraints. max_results has no min/max bounds documented. 'attachments' says 'Files that cannot be read are skipped' but no mention of size limits, path traversal validation, or supported file types.
Incomplete parameter descriptions. 'uid' in read_email says 'Email UID shown in search_emails output' but does not explain what a UID is or whether it's stable across sessions. Email format parameters (to, cc, bcc) lack validation guidance, no mention of required format or how multiple addresses are handled.