Atlas / MCP servers / garoth / SendGrid

SendGridSAFE

mcp/garoth/sendgrid

Allows AI Agents to interact with the Twilio SendGrid v3 API, managing contact lists, templates, single sends, and stats

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
21 10r · 7w · 4d
Transport
stdio
License
—
Stars
32
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server that provides access to SendGrid's Marketing API for email marketing and contact management. https://docs.sendgrid.com/api-reference/how-to-use-the-sendgrid-v3-api

Demo

In this demo, we ask the Cline SendGrid agent to make a new contact list, add my emails to it, automatically generate a template for Lost Cities facts, and send the email to the list. In this process, Cline will automatically realize that it needs to know the verified senders we have, and which unsubscribe group to use. A pretty email is delivered to my inboxes, delighting me with Lost Cities!

Important Note on API Support

This server exclusively supports SendGrid's v3 APIs and does not provide support for legacy functionality. This includes:

  • Dynamic templates only - legacy templates are not supported
  • Marketing API v3 for all contact & contact list operations
  • Single Sends API for bulk email sending

Available Tools

Contact Management

list_contacts

Lists all contacts in your SendGrid account.

// No parameters required

add_contact

Add a contact to your SendGrid marketing contacts.

{
email: string;           // Required: Contact email address
first_name?: string;     // Optional: Contact first name
last_name?: s
Read from source at commit b35177723171OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add sendgrid-mcp --env SENDGRID_API_KEY=${SENDGRID_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "sendgrid-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "SENDGRID_API_KEY": "${SENDGRID_API_KEY}"
      }
    }
  }
}
03

Exposed tools (21)

10 read · 7 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_contactwriteAdd a contact to your SendGrid marketing contacts
add_contacts_to_listwriteAdd contacts to an existing SendGrid list
create_contact_listwriteCreate a new contact list in SendGrid
create_templatewriteCreate a new email template in SendGrid
delete_contactsdestructiveDelete contacts from your SendGrid account
delete_listdestructiveDelete a contact list from SendGrid
delete_templatedestructiveDelete a dynamic template from SendGrid
get_contacts_by_listreadGet all contacts in a SendGrid list
get_single_sendwriteGet details of a specific single send
get_statsreadGet SendGrid email statistics
get_templatereadRetrieve a SendGrid template by ID
list_contact_listsreadList all contact lists in your SendGrid account
list_contactsreadList all contacts in your SendGrid account
list_single_sendsreadList all single sends in your SendGrid account
list_suppression_groupsreadList all unsubscribe groups in your SendGrid account
list_templatesreadList all email templates in your SendGrid account
list_verified_sendersreadList all verified sender identities in your SendGrid account
remove_contacts_from_listdestructiveRemove contacts from a SendGrid list without deleting them
send_emailwriteSend an email using SendGrid
send_to_listwriteSend an email to a contact list using SendGrid Single Sends
validate_emailreadValidate an email address using SendGrid
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (4)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_contacts, delete_list, delete_template, remove_contacts_from_list
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@sendgrid/client, @sendgrid/helpers, @sendgrid/mail, @types/jest, @types/node, dotenv, jest, ts-jest
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:221
- Create a new API key with full access permissions

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha b35177723171full audit observations/trust-audit/mcp-server/garoth__sendgrid.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08b35177723171SAFEB89first audit
06

Questions

What is the SendGrid MCP server?

Allows AI Agents to interact with the Twilio SendGrid v3 API, managing contact lists, templates, single sends, and stats

What tools does SendGrid expose?

21 in total: 10 read-only, 7 that write, and 4 that can delete or overwrite (delete_contacts, delete_list, delete_template, remove_contacts_from_list). Every one is listed on this page with its risk.

Is SendGrid safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does SendGrid need?

It reads SENDGRID_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does SendGrid run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as sendgrid-mcp at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (b35177723171), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement