Skip to main content
Glama

campaignstack_send_message

Destructive

Send a LinkedIn message in an existing conversation, optionally with file attachments (public URLs). Takes a conversationRef { platform, id } from campaignstack_list_inbox_conversations. The message is dispatched asynchronously via the runner. The tool returns a messageEntityUrn for tracking. Use campaignstack_get_conversation to check delivery status. Subject to daily send_message budget and business hours gates unless bypassed. When true, bypasses ALL LinkedIn safety limits (daily budget, weekly caps, business hours, account status checks). ⚠️ WARNING: This disables all protections that prevent LinkedIn account restrictions. Use only when you understand the risks and accept that the account may be flagged or restricted by LinkedIn.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
textYes
attachmentsNoUp to 5 files to attach (images or documents). Downloaded server-side and validated against the LinkedIn attachment policy.
conversationRefYes
dangerouslyBypassSafetySystemNo

Schema Changelog

Changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. First observed

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Discloses several traits beyond the annotations: the message is 'dispatched asynchronously via the runner,' it returns a messageEntityUrn for tracking, and it is 'subject to daily send_message budget and business hours gates unless bypassed.' The warning that the bypass disables 'ALL LinkedIn safety limits' and may 'flag or restrict' the account explains the destructiveHint=true annotation rather than merely restating it.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Four sentences, front-loaded with the core action, then attachments, input sourcing, async behavior, follow-up, and safety gates in decreasing priority. Every sentence carries information, and the risk warning earns its place given the destructive annotation.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 4-parameter tool with nested objects, no output schema, and destructive annotations, the description covers the action, input sourcing, return value, delivery-status follow-up, async behavior, and risk profile. Nothing an agent needs to call it correctly or avoid account harm is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

With only 25% schema description coverage, the description compensates for the gaps: it tells the agent where conversationRef comes from, clarifies that attachment URLs must be public ('public URLs'), and explains the dangerouslyBypassSafetySystem parameter in detail ('bypasses ALL LinkedIn safety limits... account may be flagged or restricted'). The required text parameter still relies mostly on inference from the tool's purpose.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific action: 'Send a LinkedIn message in an existing conversation, optionally with file attachments (public URLs).' The 'existing conversation' scoping and LinkedIn platform constraint distinguish it from sibling send tools like send_connection_request, send_inmail, and send_gmail, and the reference to campaignstack_list_inbox_conversations anchors its place in the workflow.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives clear operational context: the conversationRef must come from campaignstack_list_inbox_conversations, and campaignstack_get_conversation is named as the follow-up for checking delivery status. It does not explicitly state when to prefer send_inmail or send_connection_request over this tool, so differentiation from sending siblings is left implicit rather than stated as exclusions.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A3.7/5.0
Disambiguation3/5

The set is enormous and generally well-differentiated through detailed cross-referenced descriptions, but several clusters blur together: archive/delete/remove have inconsistent permanence semantics (delete_campaign vs remove_signal_watch vs archive_campaign), create_connection_watch_agent explicitly overlaps with set_account_watcher, and the parallel draft-checkup and playbook-proposal flows (run_draft_checkup/get_draft_checkup/accept_draft_checkup vs propose_playbook_change/get_playbook_proposal/decide_playbook_proposal) present near-identical decision pipelines.

Naming Consistency4/5

Nearly every tool follows the campaignstack_<verb>_<noun> convention with disciplined get/list pairing and consistent verb choices (create/update/delete/pause/resume). Minor deviations like campaignstack_priority_enrich (adverb+verb) and campaignstack_whoami break the strict verb_noun pattern but are isolated and do not hinder navigation.

Tool Count1/5

223 tools is an extreme surface for any MCP server. Even though each tool maps to a distinct API operation and the underlying platform is broad, the scale far exceeds the 50+ threshold for an extreme mismatch and will overwhelm agents with selection overhead.

Completeness5/5

The surface is exhaustive for the LinkedIn outreach domain: full campaign/workflow/lead-list lifecycles, ICP and persona management, content scheduling and approvals, inbox and messaging, enrichment and integrations, signal watches and exclusions, review queues, playbook versioning, workspace admin, billing, and notifications. Minor gaps like a missing delete_lead or delete_company are explained by shared-data semantics, so no critical dead ends remain.

Resources