mail_send_draft
Send an Apple Mail draft. Requires confirmation.
This record as markdown: /tools/0xatrilla-apple-mcp/mail-send-draft.md
What mail_send_draft does on Apple Apps MCP
AI agents use mail_send_draft to create or update resources in Apple Apps MCP, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Apple Apps MCP environment.
Why mail_send_draft is rated Medium
Sending email is a Write action (creates new data—sent messages and communications). Severity is high because an AI agent misusing this could send unauthorized emails, spam recipients, leak sensitive information, or damage reputation. However, it requires confirmation (stated in description), which mitigates risk slightly compared to unrestricted send capability.
From the tool's definition Tool name 'mail_send_draft' and description 'Send an Apple Mail draft' indicates the tool creates and sends email messages. This is a write operation that modifies the mailbox state by adding sent messages and potentially affecting external recipients.
Attacks that exploit this kind of access
The rule that runs mail_send_draft safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Apple Apps MCP, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For mail_send_draft, this is the rule to start with:
mail_send_draft stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Apple Apps MCP, apply this rule, and every mail_send_draft call is checked against it from then on.
Questions about mail_send_draft
Send an Apple Mail draft. Requires confirmation. It is categorised as a Write tool in the Apple Apps MCP MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
Register the Apple Apps MCP server in PolicyLayer and add a rule for mail_send_draft: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Apple Apps MCP. Nothing to install.
mail_send_draft is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the mail_send_draft rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for mail_send_draft. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
mail_send_draft is provided by the Apple Apps MCP server (0xatrilla/apple-mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Apple Apps, and thousands of servers like it.
This server
Across the catalogue