.cursor — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited .cursor (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Model Context Protocol (MCP) server and HTTP client for Mailpit — local SMTP capture and inbox inspection for development and E2E testing.
Connects to a Mailpit instance on your machine (default http://127.0.0.1:8025). No cloud services, no stored credentials in this repository.
git clone https://github.com/exabyteso/mailpit_mcp.git
cd mailpit_mcp
npm installCopy .env.example to .env locally (.env is gitignored). All configuration is optional:
| Variable | Default | Description |
|---|---|---|
MAILPIT_URL | http://127.0.0.1:8025 | Mailpit HTTP API base URL |
MAILPIT_AUTH_USER | — | Basic auth username (if enabled on Mailpit) |
MAILPIT_AUTH_PASS | — | Basic auth password |
MAILPIT_TIMEOUT_MS | 30000 | HTTP request timeout |
npm startAdd to your workspace .cursor/mcp.json:
{
"mcpServers": {
"mailpit-local": {
"command": "node",
"args": ["src/index.mjs"],
"cwd": "/absolute/path/to/mailpit_mcp",
"env": {
"MAILPIT_URL": "http://127.0.0.1:8025"
}
}
}
}When mailpit_mcp is cloned next to another project (sibling under Projects/), you can use a relative cwd from that project's workspace root.
| Tool | Description |
|---|---|
mailpit_health | GET /api/v1/info |
mailpit_list_messages | Recent messages |
mailpit_search | Mailpit search query |
mailpit_get_message | Full message by ID |
mailpit_get_latest_for_recipient | Latest mail to an address |
mailpit_wait_for_message | Poll until a message matches |
mailpit_extract_otp | Parse verification code from body |
mailpit_delete_all | Clear mailbox (test reset) |
import { createMailpitClient, extractOtp } from 'mailpit-mcp/client';
const mailpit = createMailpitClient();
await mailpit.deleteAll();
const message = await mailpit.waitForMessage({
to: '[email protected]',
timeoutMs: 10_000,
});
const code = extractOtp(message.Text ?? '');npm testUnit tests use fixtures only — no live Mailpit required.
See SECURITY.md. This repo ships no secrets. Configure auth via environment variables on your machine only.
MIT — see LICENSE.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.