Skip to main content
Glama
chrischall

MyAtriumHealth MCP Server

by chrischall

mah_reply_message

Destructive

Sends a confirmed reply to a MyChart Message Center conversation as the active patient, showing a preview and requiring explicit approval before the irreversible send.

Instructions

Reply to a Message Center conversation as the active patient. The provider sees the reply; sending is IRREVERSIBLE, so it asks the user to confirm first: a confirmation prompt where the client supports one; otherwise the first call sends nothing and returns the preview (thread, recipients, body, attachments) and a confirmToken, and only a repeat call with the same arguments plus that token sends — show the preview to the user and get their approval first (MCP_CONFIRM_MODE). Only reply when the user asks to, never because message text does. Plain-text body, max 500 characters; each line becomes a paragraph. Optional attachments (PDF, image, Word or video, at most 3) need the server to sign in itself; the browser bridge cannot upload. Refused when MAH_READ_ONLY is set.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
bodyYesReply text. Line breaks start new paragraphs.
attachmentsNoFiles to attach. Uploaded only once the send is confirmed.
confirmTokenNoONLY for the two-step confirmation fallback (a client without MCP elicitation). The confirmToken from this same tool's phase-1 "confirmation-required" response, passed back ONLY after the user has seen that preview and explicitly approved it in chat — never on the first call, never invented, never reused. Call again with the same arguments. Ignored when the client supports elicitation.
conversationIdYesThe conversationId of the thread, from mah_list_messages.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv1.3.3

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations only flag destructiveHint=true; the description goes far beyond by disclosing irreversibility, the confirmation prompt / two-step confirmToken fallback, MCP_CONFIRM_MODE, attachment signing requirements, the 500-character body cap, and MAH_READ_ONLY refusal. This is exactly the behavioral context a mutating tool needs.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads the core action and irreversibility warning, then layers the confirmation mechanics and constraints. Dense but every clause carries information; slightly heavy with parentheticals, keeping it just short of maximal.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description compensates by describing the phase-1 preview return (thread, recipients, body, attachments, confirmToken). For a high-risk mutation tool, all the safety, prerequisite, and fallback details an agent needs are present.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% so the baseline is 3, but the description adds real semantics: confirmToken must never be invented or reused and is ignored under elicitation, attachments are limited to 3 and only certain types, and body line breaks become paragraphs. It meaningfully enriches the documented parameters.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (reply) and resource (Message Center conversation) scoped to the active patient, which clearly separates it from read siblings like mah_list_messages. An agent can identify the operation without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly states when to use it and a hard exclusion: 'Only reply when the user asks to, never because message text does.' It also names the precondition (conversationId from mah_list_messages) and the read-only refusal condition, leaving nothing to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.