Atlas / MCP servers / codefuturist / Email

EmailBLOCK

mcp/codefuturist/email-16

Email MCP server with full IMAP + SMTP support — read, search, send, manage, and organize email from any AI assistant via the Model Context Protocol

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
50 32r · 13w · 5d
Transport
stdio · streamable-http
License
LGPL-3.0
Stars
125
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/RichardLitt/standard-readme) [](LICENSE) [](https://www.npmjs.com/package/@codefuturist/email-mcp) [](https://www.npmjs.com/package/@codefuturist/email-mcp) [](https://github.com/codefuturist/email-mcp/actions/workflows/ci.yml)

An MCP (Model Context Protocol) server providing comprehensive email capabilities via IMAP and SMTP.

Enables AI assistants to read, search, send, manage, schedule, and analyze emails across multiple accounts. Exposes 47 tools, 7 prompts, and 6 resources over the MCP protocol with OAuth2 support (experimental), email scheduling, calendar extraction, analytics, provider-aware label management, real-time IMAP IDLE watcher with AI-powered triage, customizable presets and static rules, and a guided setup wizard.

Highlights

Table of Contents

  • Highlights
  • Security
  • Background
  • Install
  • Usage

-

Read from source at commit d188fe5ee334OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add email-mcp -- npx -y @codefuturist/[email protected]
03

Exposed tools (50)

32 read · 13 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
CustomreadFull control. Provide your own system_prompt in config. The preset contributes nothing — you define everything.
add_labelwriteAdd a label to an email.
add_to_calendarwrite
analyze_email_for_schedulingread
apply_templatewriteApply an email template with variable substitution. Use action
bulk_actionreadBatch operation on multiple emails by UID list. Supports mark_read, mark_unread, flag, unflag, move, and delete. Max 100 IDs per call. Returns success/failure counts.
cancel_scheduledreadCancel a scheduled email. Removes it from the queue and deletes the associated draft.
check_calendar_permissionsread
check_healthreadCheck connection health, quota, and capabilities for email accounts. Useful for diagnosing issues.
check_notification_setupreadDiagnose desktop notification support on this platform.
configure_alertswriteUpdate alert/notification settings at runtime. Changes take effect immediately.
create_labelwriteCreate a new label. For ProtonMail, creates a folder under Labels/.
create_mailboxwriteCreate a new mailbox (folder). Use
create_reminderwrite
delete_emaildestructiveDelete an email. By default moves to Trash. Set permanent=true for permanent deletion (⚠️ irreversible).
delete_labeldestructiveDelete a label. For ProtonMail, deletes the label folder.
delete_mailboxdestructive⚠️ DESTRUCTIVE: Permanently delete a mailbox and ALL its contents. This cannot be undone. Use list_mailboxes to verify the folder path.
download_attachmentreadDownload an email attachment by filename. First use get_email to see available attachments and their filenames. Returns base64-encoded content for files ≤5MB.
extract_calendarreadExtract calendar events (ICS/iCalendar) from an email. Returns structured event data including time, location, attendees, and status.
extract_contactsreadExtract unique contacts from recent email headers. Returns contacts sorted by frequency (most frequent first). Useful for finding frequent correspondents or building an address book.
find_email_folderreadFind which real mailbox folder(s) an email belongs to.
forward_emailreadForward an email to new recipients with optional additional message. Original email is quoted below.
get_emailreadGet the full content of a specific email by ID.
get_email_statsreadGet email statistics and analytics for a mailbox. Shows volume, top senders, daily trends, and read/flagged counts.
get_email_statusreadGet the current read/flag/label state of an email without fetching its body.
get_emailsreadFetch the full content of multiple emails in a single call (max 20).
get_hooks_configreadGet the current AI hooks configuration including preset, rules, and custom instructions.
get_threadreadReconstruct a full email conversation thread by following References and In-Reply-To headers.
get_watcher_statusreadGet the status of IMAP IDLE watcher connections and recent activity.
list_accountsreadList all configured email accounts. Call this first to discover available account names for use with other tools.
list_calendarsread
list_emailsreadList emails in a mailbox with optional filters. Returns paginated results with metadata
list_eventsread
list_labelsreadList available labels for an email account.
list_mailboxesreadList all mailbox folders for an account with unread counts and special-use flags. Use list_accounts first to get the account name.
list_presetsreadList all available AI triage presets with their descriptions and suggested labels.
list_remindersread
list_scheduledreadList scheduled emails. Shows pending, sent, or all scheduled emails.
list_templatesreadList all available email templates. Templates are TOML files in ~/.config/email-mcp/templates/ with {{variable}} placeholders for subject and body.
mark_emailreadChange email flags — mark as read/unread, flag/unflag. Idempotent: marking an already-read email as read is a no-op.
move_emailwriteMove an email to a different mailbox folder.
remove_labeldestructiveRemove a label from an email. For ProtonMail, this removes the email from the label folder.
rename_mailboxwriteRename an existing mailbox (folder). Use list_mailboxes to see current folder paths.
reply_emailreadReply to an email with proper threading (In-Reply-To & References headers). Use get_email first to read the original.
save_draftwriteSave an email draft to the Drafts folder. Compose over time, then use send_draft to send it. Use list_emails with the Drafts mailbox to see saved drafts.
schedule_emailwriteSchedule an email to be sent at a specific time in the future. The email is queued locally and sent automatically when the time arrives.
search_emailsreadSearch emails by keyword across subject, sender, and body.
send_draftdestructiveSend an existing draft email and remove it from Drafts. The draft is fetched, sent via SMTP, then deleted. Use list_emails with the Drafts mailbox to find draft IDs.
send_emailwriteSend a new email. Supports plain text or HTML body, CC, and BCC.
test_notificationwriteSend a test desktop notification to verify that OS permissions are correctly configured.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (7 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (17)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/__integration__/helpers/seed.ts:28
tls: { rejectUnauthorized: false },
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli/config-commands.ts:82
console.log(`  password = ${'•'.repeat(8)}\n`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/main.ts:354
process.stderr.write(`  Endpoint : http://0.0.0.0:${port}/mcp\n`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/main.ts:355
process.stderr.write(`  Health   : http://0.0.0.0:${port}/health\n`);
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_email, delete_label, delete_mailbox, remove_label, send_draft
Why it matters. 5 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.goreleaser.yaml
.goreleaser.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.goreleaser.yaml.legacy
.goreleaser.yaml.legacy
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__integration__/helpers/config.ts:2
import type { AccountConfig } from '../../types/index.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__integration__/helpers/services.ts:1
import ConnectionManager from '../../connections/manager.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__integration__/helpers/services.ts:2
import RateLimiter from '../../safety/rate-limiter.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__integration__/helpers/services.ts:3
import ImapService from '../../services/imap.service.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__integration__/helpers/services.ts:4
import SmtpService from '../../services/smtp.service.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/safety/validation.test.ts:72
expect(() => validateWebhookUrl('https://127.0.0.1/hook')).toThrow('loopback or private');
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/safety/validation.test.ts:76
expect(() => validateWebhookUrl('https://10.0.0.1/hook')).toThrow('loopback or private');
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/safety/validation.test.ts:80
expect(() => validateWebhookUrl('https://172.16.0.1/hook')).toThrow('loopback or private');
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@clack/prompts, @modelcontextprotocol/sdk, imapflow, node-ical, nodemailer, smol-toml, zod, @biomejs/biome
Why it matters. 20 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
SECURITY.md:21
- **No credential storage** — passwords and tokens are read from your local config file or environment variables at runtime
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha d188fe5ee334full audit observations/trust-audit/mcp-server/codefuturist__email-16.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07d188fe5ee334BLOCKD69first audit
06

Questions

What is the Email MCP server?

Email MCP server with full IMAP + SMTP support — read, search, send, manage, and organize email from any AI assistant via the Model Context Protocol

What tools does Email expose?

50 in total: 32 read-only, 13 that write, and 5 that can delete or overwrite (delete_email, delete_label, delete_mailbox, remove_label, send_draft). Every one is listed on this page with its risk.

Is Email safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Email need?

It reads MCP_EMAIL_OAUTH2_CLIENT_ID, MCP_EMAIL_OAUTH2_CLIENT_SECRET, MCP_EMAIL_OAUTH2_PROVIDER, MCP_EMAIL_OAUTH2_REFRESH_TOKEN and MCP_EMAIL_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Email run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @codefuturist/email-mcp at 0.2.3.

How current is this page?

The grade is for one exact copy of the source (d188fe5ee334), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement