Jmap Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Jmap Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server exposing JMAP email and Sieve script operations as tools.
Built with the Go MCP SDK (go-sdk) and go-jmap library.
Tools map closely to JMAP methods. Email mutation tools provide structured convenience wrappers over Email/set patches.
| Tool | JMAP Method | Description |
|---|---|---|
mailbox_get | Mailbox/get | Get mailboxes by ID, or list all |
mailbox_set | Mailbox/set | Create, update, or destroy mailboxes |
| Tool | JMAP Method | Description |
|---|---|---|
email_query | Email/query | Search emails with filters, returns IDs and total count |
email_get | Email/get | Get full content of emails by ID |
email_create | Email/set | Create a new email draft in the Drafts mailbox |
email_move | Email/set | Move emails to a different mailbox |
email_flag | Email/set | Set or remove flags (seen, flagged, answered, draft) |
email_delete | Email/set | Delete emails (move to Trash or permanently destroy) |
| Tool | JMAP Method | Description |
|---|---|---|
identity_get | Identity/get | List sender identities (email addresses) |
| Tool | JMAP Method | Description |
|---|---|---|
email_submission_set | EmailSubmission/set | Submit a draft for delivery (requires -enable-send) |
| Tool | JMAP Method | Description |
|---|---|---|
sieve_get | SieveScript/get | List all scripts, or get one with full content (requires -enable-sieve) |
sieve_set | SieveScript/set | Create, update, or destroy Sieve scripts (requires -enable-sieve) |
sieve_validate | SieveScript/validate | Validate a Sieve script without saving (requires -enable-sieve) |
| Env var | Required | Description |
|---|---|---|
JMAP_SESSION_URL | always | JMAP session endpoint (e.g. https://api.fastmail.com/jmap/session) |
JMAP_AUTH_TOKEN | stdio mode | Bearer token for JMAP authentication |
| Flag | Default | Description |
|---|---|---|
-mode | stdio | Server mode: stdio or http |
-listen | :8080 | HTTP listen address (http mode only) |
-enable-send | false | Enable the email_submission_set tool (off by default) |
-enable-sieve | false | Enable Sieve script tools (off by default, requires JMAP server support) |
In HTTP mode, the token can be passed per-request via Authorization: Bearer <token> header or jmap_token query parameter (query parameter takes precedence).
helm install jmap-mcp oci://ghcr.io/mikluko/helm-charts/jmap-mcp \
--version 0.1.0 \
--set jmap.sessionURL="https://api.fastmail.com/jmap/session"In HTTP mode, JMAP auth tokens are passed per-request via Authorization: Bearer header or ?jmap_token= query parameter — no static tokens are stored in the cluster.
go install github.com/mikluko/jmap-mcp@latestgit clone https://github.com/mikluko/jmap-mcp.git
cd jmap-mcp
make install# stdio mode (default)
export JMAP_SESSION_URL=https://api.fastmail.com/jmap/session
export JMAP_AUTH_TOKEN=your-token
./jmap-mcp
# HTTP mode
./jmap-mcp -mode http -listen :8080make build # Build and push container image + Helm chart
make image # Build and push container image with ko
make package # Package and push Helm chart to OCI registry
make test # Run tests
make install # Install binary locally~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.