Official monorepo of SDKs, CLI, and MCP servers for Sendmux email APIs across TypeScript, Python, Go, PHP, Rust, and Ruby.
SaferSkills independently audited Sendmux Sdk (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Official SDK, CLI, and MCP workspace for Sendmux.
| Ecosystem | Package | Surface | API key or auth | Install | Source |
|---|---|---|---|---|---|
| npm | @sendmux/core | Shared TypeScript helpers | n/a | npm install @sendmux/core | packages/ts/core |
| npm | @sendmux/sending | Sending API | smx_mbx_* or owner-approved smx_agent_* | npm install @sendmux/sending | packages/ts/sending |
| npm | @sendmux/mailbox | Mailbox API | smx_mbx_* or smx_agent_* | npm install @sendmux/mailbox | packages/ts/mailbox |
| npm | @sendmux/management | Management API | smx_root_* | npm install @sendmux/management | packages/ts/management |
| npm | @sendmux/sdk | TypeScript umbrella package | surface-specific | npm install @sendmux/sdk | packages/ts/sdk |
| npm | @sendmux/cli | sendmux CLI | command/profile-specific | npm install -g @sendmux/cli | packages/ts/cli |
| Homebrew | sendmux | sendmux CLI | command/profile-specific | brew install sendmux/tap/sendmux | Sendmux/homebrew-tap |
| PyPI | sendmux-core | Shared Python helpers | n/a | pip install sendmux-core | packages/python/core |
| PyPI | sendmux-sending | Sending API | smx_mbx_* or owner-approved smx_agent_* | pip install sendmux-sending | packages/python/sending |
| PyPI | sendmux-mailbox | Mailbox API | smx_mbx_* or smx_agent_* | pip install sendmux-mailbox | packages/python/mailbox |
| PyPI | sendmux-management | Management API | smx_root_* | pip install sendmux-management | packages/python/management |
| PyPI | sendmux-sdk | Python umbrella package | surface-specific | pip install sendmux-sdk | packages/python/sdk |
| PyPI | sendmux-mcp | Local, self-hosted, and hosted MCP servers | OAuth for hosted; surface-specific keys for local | pip install sendmux-mcp | packages/python/mcp |
| Go | sendmux.ai/go/core | Shared Go helpers | n/a | go get sendmux.ai/[email protected] | go/core |
| Go | sendmux.ai/go/sending | Sending API | smx_mbx_* or owner-approved smx_agent_* | go get sendmux.ai/[email protected] | go/sending |
| Go | sendmux.ai/go/mailbox | Mailbox API | smx_mbx_* or smx_agent_* | go get sendmux.ai/[email protected] | go/mailbox |
| Go | sendmux.ai/go/management | Management API | smx_root_* | go get sendmux.ai/[email protected] | go/management |
| Go | sendmux.ai/go/sdk | Go umbrella package | surface-specific | go get sendmux.ai/[email protected] | go/sdk |
| crates.io | sendmux | Rust umbrella crate | surface-specific | cargo add sendmux | rust |
| Packagist | sendmux/core | Shared PHP helpers | n/a | composer require sendmux/core:^1.0 | packages/php/core |
| Packagist | sendmux/sending | Sending API | smx_mbx_* or owner-approved smx_agent_* | composer require sendmux/sending:^1.0 | packages/php/sending |
| Packagist | sendmux/mailbox | Mailbox API | smx_mbx_* or smx_agent_* | composer require sendmux/mailbox:^1.0 | packages/php/mailbox |
| Packagist | sendmux/management | Management API | smx_root_* | composer require sendmux/management:^1.0 | packages/php/management |
| Packagist | sendmux/sdk | PHP umbrella package | surface-specific | composer require sendmux/sdk:^1.0 | packages/php/sdk |
| RubyGems | sendmux-core | Shared Ruby helpers | n/a | gem install sendmux-core | packages/ruby/core |
| RubyGems | sendmux-sending | Sending API | smx_mbx_* or owner-approved smx_agent_* | gem install sendmux-sending | packages/ruby/sending |
| RubyGems | sendmux-mailbox | Mailbox API | smx_mbx_* or smx_agent_* | gem install sendmux-mailbox | packages/ruby/mailbox |
| RubyGems | sendmux-management | Management API | smx_root_* | gem install sendmux-management | packages/ruby/management |
| RubyGems | sendmux-sdk | Ruby umbrella package | surface-specific | gem install sendmux-sdk | packages/ruby/sdk |
Install only the package for the surface you need.
npm install @sendmux/sending
pip install sendmux-sending
go get sendmux.ai/[email protected]
cargo add sendmux
composer require sendmux/sending:^1.0
gem install sendmux-sendingUse send-capable smx_mbx_* keys or owner-approved Sending-resource smx_agent_* tokens for Sending clients. Use smx_mbx_* keys or scoped smx_agent_* tokens for Mailbox clients. Use root smx_root_* keys for Management clients. Agent tokens remain limited by server-side scopes; pre-claim self-registered agent tokens do not include email.send.
For command-line access, install the CLI:
brew install sendmux/tap/sendmux
npm install -g @sendmux/cli
sendmux --helpFor MCP clients, install sendmux-mcp or connect to the hosted MCP endpoint:
pip install sendmux-mcp
sendmux-mcp-mailbox --helpThe hosted MCP endpoint is https://mcp.sendmux.ai/mcp. Local MCP commands support stdio and HTTP transports; hosted MCP uses OAuth.
| Path | Purpose |
|---|---|
packages/ts | TypeScript SDK packages and the sendmux CLI. |
packages/python | Python SDK packages and the sendmux-mcp package. |
go | Go module sendmux.ai/go and subpackages. |
rust | Rust crate published as sendmux on crates.io. |
packages/php | PHP package sources used for Packagist packages and public split repositories. |
packages/ruby | RubyGem package sources. |
codegen | Generator configuration and templates. |
scripts | Generation, verification, publishing, and release helper scripts. |
docs | Surface-coverage and live E2E audit artefacts. |
.github/workflows | CI, canary, live E2E, and release workflows. |
SDK packages track the Sendmux public API contracts. Patch versions can differ between packages when a fix only affects one ecosystem or runtime.
Generated clients are built from committed OpenAPI snapshots. Any API contract change must update the snapshots and generated output in the same change.
For help, open a GitHub issue with the package name, version, command or import path, and the request ID from any API error response.
Open pull requests against this repository. Keep generated output, source snapshots, and verification artefacts together in the same change.
Security issues should be reported through GitHub Security Advisories.
This repository is available under the MIT licence.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.