agent-email-cli — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited agent-email-cli (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill to operate the agent-email command safely and predictably for agent workflows that need inbox access.
Prefer JSON-native command output and return key fields (email, messageId, subject, createdAt, from.address) in your summaries.
command -v agent-email
agent-email --helpIf missing, install:
npm install -g @zaddy6/agentemail
# or
bun install -g @zaddy6/agentemailagent-email createRecord these fields from JSON output:
data.emaildata.accountIddata.activeEmailDo not record, repeat, or print secret values such as mailbox passwords or tokens.
agent-email read <email|default>For inbox waiting/polling:
agent-email read <email|default> --wait 30 --interval 2For full message payloads:
agent-email read <email|default> --fullagent-email show <email|default> <messageId>Use show when you need body/source details for verification links, codes, or full content extraction.
agent-email accounts list
agent-email use <email|default>
agent-email accounts remove <email>Avoid commands that require entering secrets on the command line in agent logs.
agent-email delete <email|default> <messageId>default alias when user does not specify an email.password, token) from command output.code and hint fields directly.AUTH_REQUIRED/401), rerun command once and request user intervention if credentials must be re-established.RATE_LIMITED/429), retry after short delay.command not found: ensure ~/.bun/bin or npm global bin path is on PATH.NO_ACTIVE_ACCOUNT: run agent-email create or agent-email use <email>.ACCOUNT_NOT_FOUND: run agent-email accounts list and pick a valid address.EOTP during npm publish: use npm trusted publishing for CI or publish locally with OTP.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.