Mailbox Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mailbox Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Give your AI tools access to your email. Search, read, send, and manage messages across multiple accounts without leaving your terminal.
mailbox-mcp is an MCP server that connects your email to Claude Code, Cursor, Windsurf, or any AI tool that supports the Model Context Protocol. Instead of switching between your terminal and Gmail, you ask the AI to find that invoice, summarize a thread, or draft a reply — and it does.
What makes this different from the 60+ other email MCP servers:
Add to your Claude Code MCP config (~/.claude.json). The package runs straight from npm via npx:
{
"mcpServers": {
"mailbox": {
"command": "npx",
"args": ["-y", "mailbox-mcp"],
"env": {
"MAILBOX_MCP_PASSPHRASE": "a-long-random-passphrase"
}
}
}
}MAILBOX_MCP_PASSPHRASE is the passphrase used to encrypt IMAP/JMAP credentials at rest; it's required before adding an IMAP or JMAP account, and unused for Gmail-only setups.
<details> <summary>From source instead</summary>
git clone https://github.com/jgalea/mailbox-mcp.git
cd mailbox-mcp
npm install && npm run buildThen point the config at the build with "command": "node", "args": ["/path/to/mailbox-mcp/dist/server.js"]. </details>
#### 1. Create a Google Cloud project
#### 2. Set up OAuth consent screen
@gmail.com address you use to authenticate, not a workspace alias)#### 3. Create OAuth credentials
~/.mailbox-mcp/oauth-keys.json#### 4. Authenticate
In Claude Code, run: authenticate alias="personal" provider="gmail" email="[email protected]"
This opens a browser window to complete the OAuth flow. Your tokens are stored locally in ~/.mailbox-mcp/accounts/.
In Claude Code, run:
authenticate alias="work" provider="imap" email="[email protected]" host="imap.company.com" smtpHost="smtp.company.com" username="[email protected]" password="your-app-password"Credentials are encrypted at rest using AES-256-GCM.
In Claude Code, run:
authenticate alias="fastmail" provider="jmap" email="[email protected]" host="fastmail.com" username="[email protected]" password="your-app-password"JMAP auto-discovers the API endpoint via .well-known/jmap. Credentials are encrypted at rest using AES-256-GCM.
Supported JMAP servers: Fastmail, Stalwart, Topicbox, Cyrus IMAP, and any RFC 8620-compliant server.
JMAP advantages over IMAP:
| Tool | Description |
|---|---|
list_accounts | List configured accounts |
authenticate | Add a new account |
reauth | Re-run OAuth for an existing Gmail account (use when refresh token expires with invalid_grant) |
remove_account | Remove an account |
search_emails | Search messages (optional folder to scope the search) |
multi_account_search | Run the same query across every configured account in parallel |
read_email | Read a message |
read_thread | Read a conversation thread (Gmail + JMAP) |
send_email | Send a new email (supports attachments) |
reply_email | Reply to a message (supports attachments) |
forward_email | Forward a message (supports attachments) |
create_draft | Create a draft (supports reply drafts via in_reply_to, attachments) |
list_drafts | List drafts for an account |
send_draft | Send an existing draft |
trash_emails | Trash messages |
mark_read | Mark a message as read or unread |
star_email | Star or unstar a message |
archive_email | Archive a message (remove from inbox) |
list_labels | List labels/folders |
create_label | Create a label/folder |
delete_label | Delete a label/folder |
modify_email | Modify message labels |
batch_modify_emails | Bulk modify labels |
count_unread_by_label | Show unread message counts per label/folder |
download_attachment | Download an attachment |
export_email | Save a message as a .eml file |
export_thread | Save every message in a thread as .eml files (Gmail + JMAP) |
emails_since | List messages received after a given timestamp |
inbox_summary | Inbox overview |
| Tool | Description |
|---|---|
create_filter | Create a filter |
list_filters | List filters |
delete_filter | Delete a filter |
save_template | Save a template |
list_templates | List templates |
delete_template | Delete a template |
send_template | Send from template |
get_signature | Get signature |
set_signature | Update signature |
get_vacation | Get vacation settings |
set_vacation | Configure vacation reply (supports date ranges, domain-only) |
unsubscribe | Find unsubscribe link |
bulk_unsubscribe | Bulk unsubscribe |
list_send_as | List send-as aliases |
send_email, reply_email, forward_email, and create_draft accept an optional attachments parameter — an array of local file paths. The server reads each file, detects its MIME type from the extension, and embeds it in the outgoing message (or draft).
send_email account="personal" to=["[email protected]"] subject="The report" body="See attached." attachments=["/path/to/report.pdf", "/path/to/chart.png"]MIT
Built at AgentVania.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.