# gmail_send_message_with_attachment

A write tool on the Gmail MCP Server MCP server.

Agent View of the PolicyLayer registry record for `gmail_send_message_with_attachment`. HTML page: https://policylayer.com/tools/ampcome-mcps-gmail-mcp/gmail-send-message-with-attachment

## Facts

- Tool: `gmail_send_message_with_attachment`
- Server: Gmail MCP Server (`ampcome-mcps/gmail-mcp`) — https://policylayer.com/tools/ampcome-mcps-gmail-mcp.md
- Homepage: https://github.com/ampcome-mcps/gmail-mcp
- Risk category: Write (Medium risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Rate-limited

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "gmail_send_message_with_attachment",
    "arguments": {}
  }
}
```

## Why gmail_send_message_with_attachment is rated Medium

Sending emails is a reversible write operation that creates new data (messages) in a user's account and potentially affects external recipients. While not destructive or financial in nature, it carries high severity because an AI agent could send spam, phishing messages, or inappropriately disclose sensitive information to unintended recipients.

From the tool's own definition: "Tool name 'gmail_send_message_with_attachment' indicates creation of new email messages with attachments. Server description confirms 'sending' emails is a core capability."

## Use case

AI agents use gmail_send_message_with_attachment to create or update resources in Gmail MCP Server, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Gmail MCP Server environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Gmail MCP Server:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "gmail_send_message_with_attachment": {
      "limits": [
        {
          "counter": "gmail_send_message_with_attachment_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Gmail MCP Server (7)

- `gmail_delete_messages` — Destructive — https://policylayer.com/tools/ampcome-mcps-gmail-mcp/gmail-delete-messages.md
- `gmail_get_message` — Read — https://policylayer.com/tools/ampcome-mcps-gmail-mcp/gmail-get-message.md
- `gmail_get_stats` — Read — https://policylayer.com/tools/ampcome-mcps-gmail-mcp/gmail-get-stats.md
- `gmail_list_messages` — Read — https://policylayer.com/tools/ampcome-mcps-gmail-mcp/gmail-list-messages.md
- `gmail_search_messages` — Read — https://policylayer.com/tools/ampcome-mcps-gmail-mcp/gmail-search-messages.md
- `gmail_mark_as_read` — Write — https://policylayer.com/tools/ampcome-mcps-gmail-mcp/gmail-mark-as-read.md
- `gmail_send_message` — Write — https://policylayer.com/tools/ampcome-mcps-gmail-mcp/gmail-send-message.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=ampcome-mcps-gmail-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/ampcome-mcps-gmail-mcp
