Skip to main content
Glama
AndresMinakata

LinkedIn MCP Server

Send Message

send_message
Destructive

Compose and send a new LinkedIn direct message to a messageable recipient via profile-based targeting; not for replying in existing recruiter, InMail, or messaging threads.

Instructions

Compose and send a new message to a LinkedIn user.

Profile-based targeting opens LinkedIn's compose flow. It is not a safe reply path for an existing recruiter/InMail or messaging thread: it may create a separate DM even after you inspect that thread with get_conversation or search_conversations. Those tools only read an existing thread; they do not send a reply. Until a thread-targeted send path is available, do not treat profile-based send_message as a reply.

The recipient must be directly messageable from the profile page. If LinkedIn does not expose a normal Message action, use connect_with_person first, then retry send_message only after the connection request is accepted. Recipient authorization comes from validating one recipient-specific Message action carrying the target URN, then following its browser navigation and pinning the exact final route. Visible profile links or recipient URNs in the composer are optional corroboration; any contradiction fails closed. No Voyager or other private API is used. This is a write operation when confirm_send is True.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
messageYesSingle-line message text to send. C0 control characters and DEL are rejected, including CR, LF, and tab.
profile_urnNoOptional profile URN (e.g. ACoAAB...) to verify against the URN exposed by the loaded profile before opening its Message action. It never bypasses recipient verification. Obtain via get_person_profile. Note: inbox may not always show all messages; use search_conversations as a fallback.
confirm_sendYesMust be True to send the message
linkedin_usernameYesLinkedIn username of the recipient; a full profile URL is accepted too

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv4.26.0

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare destructiveHint=true and openWorldHint=true, but the description adds rich behavioral context: profile-based send may create a separate DM even after inspecting a thread; recipient must be directly messageable; it falls back to connect_with_person; authorization requires validating a recipient-specific Message action and following browser navigation; contradictions fail closed; no private API is used; and it is a write operation when confirm_send is True. These details go well beyond the annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is front-loaded with the core purpose, then expands into critical safety and usage caveats. It is longer than typical but every major section addresses a distinct concern (reply vs new DM, recipient eligibility, authorization, write condition). There is minor repetition around 'not a reply path,' but overall it is well-structured and earns its length.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool is a write operation with open-world and destructive implications, and an output schema already exists to explain return values, the description covers all necessary context: what it does, when to use it, when not to, how recipient authorization works, fallback behavior, and the confirm_send condition. Nothing critical for correct invocation is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents all four parameters in detail. The description adds some contextual meaning (e.g., confirm_send being required for write, profile_urn used for verification) but does not provide syntax, format, or additional semantic constraints beyond what the schema already states. The baseline score of 3 is appropriate when the schema carries the parameter documentation.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description explicitly states the specific verb and resource: 'Compose and send a new message to a LinkedIn user.' It also distinguishes this tool from thread-reading siblings by clarifying it is not a reply path for existing conversations. An agent can immediately tell what this tool does and how it differs from get_conversation or search_conversations.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives explicit when-to-use guidance (profile-based targeting to send a new message), when-not-to-use guidance (not a safe reply path; do not treat as a reply), and alternatives (use connect_with_person first if no Message action, and note that get_conversation/search_conversations only read threads). This is a complete routing guide.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.