Blip — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Blip (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Instant disposable email inboxes. API, CLI, MCP server, and web app.
[useblip.email](https://useblip.email) | [Docs](https://useblip.email/docs) | [API Reference](https://useblip.email/docs/api)
blip/
server/core/ Kotlin/Ktor API server (AGPL-3.0)
cli/ Kotlin/Clikt CLI
mcp-server/ TypeScript MCP server (npm: @useblip/email)
shared-models/ Shared Kotlin data modelsNo setup required. Create inboxes at app.useblip.email or via the API:
# Get a session token
curl -X POST https://api.useblip.email/v1/sessions
# Create an inbox
curl -X POST https://api.useblip.email/v1/inboxes \
-H "Authorization: Bearer <token>"brew install bmcreations/tap/blip
blip create
blip inbox --watchPrerequisites: JDK 21+, libSQL (sqld)
git clone https://github.com/blipemail/blip.git
cd blip
./gradlew :server:core:buildFatJar
# Start libSQL
sqld --http-listen-addr 127.0.0.1:8081 &
# Run the server
TURSO_URL=http://localhost:8081 WORKER_SECRET=dev-secret \
java -jar server/core/build/libs/*-all.jarOr with Docker:
docker build -t blip .
docker run -p 8080:8080 \
-e TURSO_URL=http://host.docker.internal:8081 \
-e WORKER_SECRET=your-secret \
blip| Variable | Required | Default | Description |
|---|---|---|---|
PORT | No | 8080 | Server port |
TURSO_URL | Yes | http://localhost:8081 | libSQL/Turso database URL |
TURSO_AUTH_TOKEN | No | — | Turso auth token (production) |
WORKER_SECRET | Yes | dev-secret | Shared secret for authenticating inbound email delivery |
FRONTEND_URL | No | http://localhost:4321 | Frontend URL for CORS |
See CONTRIBUTING.md for development setup and contribution guidelines.
# Run tests
./gradlew :server:core:test
# Build CLI
./gradlew :cli:installDist
./cli/build/install/cli/bin/cli --help
# Build MCP server
cd mcp-server && npm install && npm run buildThis repository uses per-component licensing:
The API server is AGPL-3.0 to ensure modifications to the hosted service remain open source. The MCP server, CLI, and shared models are MIT for maximum adoption flexibility.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.