List attachments
attachments.listList the attachments of an email (metadata only).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| mailId | Yes | Mail ID | |
| mailboxId | Yes | Mailbox ID |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| items | Yes |
attachments.listList the attachments of an email (metadata only).
| Name | Required | Description | Default |
|---|---|---|---|
| mailId | Yes | Mail ID | |
| mailboxId | Yes | Mailbox ID |
| Name | Required | Description | Default |
|---|---|---|---|
| items | Yes |
Changes observed during successful MCP inspections. Dates show when Glama detected each change.
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint and destructiveHint false. The description adds that it returns only metadata, which is useful context. However, it doesn't disclose pagination, ordering, or how many attachments, but that's covered by the output schema presumably.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Single sentence, front-loaded with the action and resource. No wasted words.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple list tool with two required parameters, a clear purpose, and an output schema, the description is adequate but minimal. It lacks any usage context or alternative differentiation, but that's not critical for a straightforward read-only listing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Both parameters have generic descriptions in the schema ('Mail ID', 'Mailbox ID'). The tool description does not add any additional meaning or format clarifications. Baseline 3 for high coverage is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states a specific verb ('List') and a specific resource ('attachments of an email'), and the parenthetical '(metadata only)' further distinguishes it from attachment retrieval. It is distinguishable from sibling tools like attachments.get which likely returns the attachment content.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives no explicit guidance on when to use this tool over alternatives. It only implies usage when you need to see what attachments an email has, but doesn't state when not to use it or name alternative tools.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Add one secure layer between your agents and this server.
The resource namespaces make most tools easy to tell apart, and each action has a clear target. A couple of boundary cases exist, such as attachments.add versus mails.inject, since both relate to putting files on a simulated email, but descriptions mostly resolve the ambiguity.
Every tool follows the same resource.action convention, and the action verbs are predictable across the set, including delete_bulk and rotate_secret. The pattern is uniform even across different resource families, making the API very predictable.
With 40 tools, the surface is quite large for an MCP server, even though the namespaces are clean. Many singular and bulk delete variants could be combined or expressed as parameters to reduce the count, so the set feels heavier than it needs to be.
The server covers the main lifecycle needs for mailboxes, emails, attachments, archived mailboxes, domains, identities, OAuth clients, and team management. Minor gaps remain, such as no mailbox update/rename, no manual archive action, and no invitation acceptance endpoint, but agents can work around these.