Atlas / MCP servers / datacovey / NornWeave

NornWeaveCAUTION

mcp/datacovey/nornweave

An open-source, self-hosted API that turns standard email providers (Mailgun, SES, SendGrid) into "Inbox-as-a-Service" for AI Agents.

Verdict
CAUTION
Grade
C
Trust score
79 /100
Exposed tools
8 5r · 3w · 0d
Transport
sse · stdio · streamable-http
License
Apache-2.0
Stars
29
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

NornWeave

"Laws they made there, and life allotted / To the sons of men, and set their fates."

  • Voluspa (The Prophecy of the Seeress), Poetic Edda, Stanza 20

Open-source, self-hosted Inbox-as-a-Service API for AI Agents

What is NornWeave?

Standard email APIs are stateless and built for transactional sending. NornWeave adds a stateful layer (Inboxes, Threads, History) and an intelligent layer (Markdown parsing, Semantic Search) to make email consumable by LLMs via REST or MCP.

In Norse mythology, the Norns (Urdr, Verdandi, and Skuld) dwell at the base of Yggdrasil, the World Tree. They weave the tapestry of fate for all beings. Similarly, NornWeave:

  • Takes raw "water" (incoming email data streams)
  • Weaves disconnected messages into coherent Threads (the Tapestry)
  • Nourishes AI Agents with clean, structured context

Features

Foundation (The Mail Proxy)

  • Virtual Inboxes: Create email addresses for your AI agents
  • Webhook Ingestion: Receive emails from Mailgun, SES, SendGrid, Resend
  • IMAP/SMTP: Poll existing mailboxes (IMAP) and send via SMTP for any provider or self-hosted server
  • Persistent Storage: SQLite (default) or PostgreSQL with abstracted storage adapters
  • Email Sending: Send replies through your configured provider

Intelligence (The Agent Layer)

  • Content Parsing: HTML to clean Markdown, cruft removal
  • Threading: Aut
Read from source at commit 47895d191638OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add n8n-nodes-nornweave --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y @nornweave/[email protected]
claude-desktop
{
  "mcpServers": {
    "n8n-nodes-nornweave": {
      "command": "npx",
      "args": [
        "-y",
        "@nornweave/[email protected]"
      ],
      "env": {
        "OPENAI_API_KEY": "${OPENAI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (8)

5 read · 3 write · 0 destructive.

ToolRiskDescription
tool_create_inboxwriteCreate a new inbox.
tool_get_attachment_contentreadGet attachment content as base64.
tool_list_attachmentsreadList attachments for a message, thread, or inbox.
tool_list_messagesreadList messages with flexible filters.
tool_search_emailreadSearch for emails with flexible filters.
tool_send_emailwriteSend an email.
tool_send_email_with_attachmentswriteSend an email with attachments.
tool_wait_for_replyreadWait for a reply in a thread (experimental).
04

Trust audit

CAUTIONgrade C · trust 79/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)WARN
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (8 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

MEDIUMPrompt injection · prompt.hidden_style · CWE-94, CWE-1427
web/content/_index.md:95
<p style="font-size: 0.875rem; color: #6b7280; font-style: italic;">
MEDIUMPrompt injection · prompt.hidden_style · CWE-94, CWE-1427
web/content/_index.md:99
<p style="font-size: 0.875rem; color: #6b7280; margin-top: 0.5rem;">
MEDIUMPrompt injection · prompt.hidden_style · CWE-94, CWE-1427
web/content/_index.md:104
<p style="font-size: 0.75rem; color: #9ca3af;">
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
openspec/changes/archive/2026-02-03-implement-n8n-node/.openspec.yaml
.openspec.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
openspec/changes/archive/2026-02-03-implement-sendgrid-adapter/.openspec.yaml
.openspec.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
openspec/changes/archive/2026-02-03-implement-ses-adapter/.openspec.yaml
.openspec.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
openspec/changes/archive/2026-02-04-implement-mcp-server/.openspec.yaml
.openspec.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/n8n-nodes-nornweave/nodes/NornWeave/NornWeave.node.ts:11
icon: 'file:../../icons/nornweave.svg',
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/n8n-nodes-nornweave/nodes/NornWeaveTrigger/NornWeaveTrigger.node.ts:14
icon: 'file:../../icons/nornweave.svg',
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/e2e/n8n/setup.sh:5
NODE_PKG_DIR="$SCRIPT_DIR/../../../packages/n8n-nodes-nornweave"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/integration/test_api/test_attachments.py:347
malicious_key = "../../etc/passwd"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
web/content/docs/getting-started/installation.md:199
proxy_pass http://127.0.0.1:8000;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
web/content/docs/getting-started/installation.md:204
proxy_pass http://127.0.0.1:8000;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
web/content/docs/getting-started/installation.md:223
proxy_pass http://127.0.0.1:8000;
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/nornweave/adapters/demo.py:122
content = base64.b64decode(content)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/nornweave/adapters/sendgrid.py:431
signature_bytes = base64.b64decode(signature)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/nornweave/adapters/sendgrid.py:438
public_key_bytes = base64.b64decode(self._webhook_public_key)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/nornweave/adapters/ses.py:546
signature = base64.b64decode(signature_b64)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/nornweave/adapters/ses.py:606
content_bytes = base64.b64decode(content)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
.cursor/skills/mcp-builder/scripts/requirements.txt
anthropic, mcp
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/n8n-nodes-nornweave/package.json
@eslint/js, @n8n/node-cli, @types/jest, eslint, jest, release-it, ts-jest
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
openspec/changes/archive/2026-02-06-imap-smtp-connector/proposal.md:26
- **Per-inbox provider configuration**: All inboxes share the same IMAP/SMTP server credentials. Multi-server or mixed-provider setups are out of scope.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
web/content/docs/guides/mailgun.md:3
description: "Complete guide to integrating Mailgun with NornWeave. Domain verification, DNS setup, webhook configuration, and API credentials for AI agent email."
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
web/content/docs/guides/resend.md:3
description: "Step-by-step Resend integration with NornWeave. API key creation, domain verification, webhook setup for receiving emails for AI agent email."
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 47895d191638full audit observations/trust-audit/mcp-server/datacovey__nornweave.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0847895d191638CAUTIONC79first audit
06

Questions

What is the NornWeave MCP server?

An open-source, self-hosted API that turns standard email providers (Mailgun, SES, SendGrid) into "Inbox-as-a-Service" for AI Agents.

What tools does NornWeave expose?

8 in total: 5 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is NornWeave safe to connect to an agent?

With care. The audit graded it C (79/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does NornWeave need?

It reads OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does NornWeave run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @nornweave/n8n-nodes-nornweave at 0.1.2.

How current is this page?

The grade is for one exact copy of the source (47895d191638), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement