NornWeaveCAUTION
An open-source, self-hosted API that turns standard email providers (Mailgun, SES, SendGrid) into "Inbox-as-a-Service" for AI Agents.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
NornWeave
"Laws they made there, and life allotted / To the sons of men, and set their fates."
- Voluspa (The Prophecy of the Seeress), Poetic Edda, Stanza 20
Open-source, self-hosted Inbox-as-a-Service API for AI Agents
What is NornWeave?
Standard email APIs are stateless and built for transactional sending. NornWeave adds a stateful layer (Inboxes, Threads, History) and an intelligent layer (Markdown parsing, Semantic Search) to make email consumable by LLMs via REST or MCP.
In Norse mythology, the Norns (Urdr, Verdandi, and Skuld) dwell at the base of Yggdrasil, the World Tree. They weave the tapestry of fate for all beings. Similarly, NornWeave:
- Takes raw "water" (incoming email data streams)
- Weaves disconnected messages into coherent Threads (the Tapestry)
- Nourishes AI Agents with clean, structured context
Features
Foundation (The Mail Proxy)
- Virtual Inboxes: Create email addresses for your AI agents
- Webhook Ingestion: Receive emails from Mailgun, SES, SendGrid, Resend
- IMAP/SMTP: Poll existing mailboxes (IMAP) and send via SMTP for any provider or self-hosted server
- Persistent Storage: SQLite (default) or PostgreSQL with abstracted storage adapters
- Email Sending: Send replies through your configured provider
Intelligence (The Agent Layer)
- Content Parsing: HTML to clean Markdown, cruft removal
- Threading: Aut
47895d191638OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add n8n-nodes-nornweave --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y @nornweave/[email protected]{
"mcpServers": {
"n8n-nodes-nornweave": {
"command": "npx",
"args": [
"-y",
"@nornweave/[email protected]"
],
"env": {
"OPENAI_API_KEY": "${OPENAI_API_KEY}"
}
}
}
}Exposed tools (8)
5 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
tool_create_inbox | write | Create a new inbox. |
tool_get_attachment_content | read | Get attachment content as base64. |
tool_list_attachments | read | List attachments for a message, thread, or inbox. |
tool_list_messages | read | List messages with flexible filters. |
tool_search_email | read | Search for emails with flexible filters. |
tool_send_email | write | Send an email. |
tool_send_email_with_attachments | write | Send an email with attachments. |
tool_wait_for_reply | read | Wait for a reply in a thread (experimental). |
Trust audit
CAUTIONgrade C · trust 79/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | WARN |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (8 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
<p style="font-size: 0.875rem; color: #6b7280; font-style: italic;">
<p style="font-size: 0.875rem; color: #6b7280; margin-top: 0.5rem;">
<p style="font-size: 0.75rem; color: #9ca3af;">
.pre-commit-config.yaml
.openspec.yaml
.openspec.yaml
.openspec.yaml
.openspec.yaml
icon: 'file:../../icons/nornweave.svg',
icon: 'file:../../icons/nornweave.svg',
NODE_PKG_DIR="$SCRIPT_DIR/../../../packages/n8n-nodes-nornweave"
malicious_key = "../../etc/passwd"
proxy_pass http://127.0.0.1:8000;
proxy_pass http://127.0.0.1:8000;
proxy_pass http://127.0.0.1:8000;
content = base64.b64decode(content)
signature_bytes = base64.b64decode(signature)
public_key_bytes = base64.b64decode(self._webhook_public_key)
signature = base64.b64decode(signature_b64)
content_bytes = base64.b64decode(content)
anthropic, mcp
@eslint/js, @n8n/node-cli, @types/jest, eslint, jest, release-it, ts-jest
- **Per-inbox provider configuration**: All inboxes share the same IMAP/SMTP server credentials. Multi-server or mixed-provider setups are out of scope.
description: "Complete guide to integrating Mailgun with NornWeave. Domain verification, DNS setup, webhook configuration, and API credentials for AI agent email."
description: "Step-by-step Resend integration with NornWeave. API key creation, domain verification, webhook setup for receiving emails for AI agent email."
Gates applied: no_behavioural_pass.
47895d191638full audit observations/trust-audit/mcp-server/datacovey__nornweave.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 47895d191638 | CAUTION | C | 79 | first audit |
Questions
What is the NornWeave MCP server?
An open-source, self-hosted API that turns standard email providers (Mailgun, SES, SendGrid) into "Inbox-as-a-Service" for AI Agents.
What tools does NornWeave expose?
8 in total: 5 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is NornWeave safe to connect to an agent?
With care. The audit graded it C (79/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does NornWeave need?
It reads OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does NornWeave run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @nornweave/n8n-nodes-nornweave at 0.1.2.
How current is this page?
The grade is for one exact copy of the source (47895d191638), read on 2026-10-08. The repository is watched and re-audited when it changes.