Atlas / MCP servers / googlarz / Proton Mail Bridge Client

Proton Mail Bridge ClientBLOCK

mcp/googlarz/proton-mail-bridge-client

Local-first Proton Mail MCP server and CLI via Proton Bridge. Search, draft, send and organize mail from Claude Desktop, Claude Code or any MCP client. 96 tools, read-only and send-to-self modes.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
60 25r · 21w · 14d
Transport
stdio
License
MIT
Stars
69
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

____  ____   ___ _____ ___  _   _   __  __    _    ___ _
|  _ \|  _ \ / _ \_   _/ _ \| \ | | |  \/  |  / \  |_ _| |
| |_) | |_) | | | || || | | |  \| | | |\/| | / _ \  | || |
|  __/|  _ <| |_| || || |_| | |\  | | |  | |/ ___ \ | || |___
|_|   |_| \_\\___/ |_| \___/|_| \_| |_|  |_/_/   \_\___|_____|
Bridge Client  ·  CLI + Claude Desktop MCP for Proton Mail

[](https://www.npmjs.com/package/proton-mail-bridge-client) [](https://github.com/googlarz/proton-mail-bridge-client/actions/workflows/ci.yml) [](LICENSE) [](https://nodejs.org) [](https://www.typescriptlang.org) [](https://modelcontextprotocol.io) [](https://github.com/googlarz/proton-mail-bridge-client) [](https://github.com/googlarz/proton-mail-bridge-client/commits/main) [](https://github.com/googlarz/proton-mail-bridge-client) [](https://glama.ai/mcp/servers/googlarz/proton-mail-bridge-client)

Give Claude Desktop (or Cline, or any MCP client) full access to your Proton Mail inbox: read, search, send, draft, triage threads, manage folders, save

Read from source at commit a27d1c5fe30aOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add proton-mail-bridge-client --env PROTONMAIL_PASSWORD=${PROTONMAIL_PASSWORD} -- npx -y [email protected]
03

Exposed tools (60)

25 read · 21 write · 14 destructive. Blast radius: 14 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
areaddesc
archive_emailwriteMove a single email to the standard Archive folder. Use for messages that are resolved but worth keeping long-term. Prefer trash_email when the message is no longer needed. Prefer move_email to route to a custom folder. Prefer batch_email_action for archiving multiple emails at once.
breaddesc
bulk_movewriteMove multiple emails to a target folder in one IMAP pass. Accepts either explicit emailIds[] or a match criteria object (XOR). Supports dryRun to preview. For single-message moves use move_email.
bulk_update_labelsdestructiveAdd or remove Proton labels on multiple messages simultaneously. Use when the same label change should apply to several messages. Labels are IMAP folders under Labels/ namespace. Accepts emailIds[] OR match+folder (XOR).
cancel_reply_reminderdestructiveDelete a reply reminder by the id set_reply_reminder or list_reply_reminders gave.
cancel_sendwriteCancel a send_email call that was queued because PROTONMAIL_SEND_DELAY_SECONDS is set. Only works while the item is still pending — once it has actually sent, this returns canceled: false. No effect (throws) if PROTONMAIL_SEND_DELAY_SECONDS is 0, since nothing is ever queued in that case.
cancel_snoozereadWake a snoozed email immediately, moving it back to its original folder before wakeAt. No effect (throws) if the snooze has already woken or was already canceled.
clear_cachedestructiveEvict all in-memory caches: folder list, message metadata, and analytics data. Use when cached data appears stale after external mailbox changes (e.g. folders modified via Proton webmail). Does NOT affect the persistent SQLite index — use clear_index for that.
clear_indexdestructiveDelete the entire persistent SQLite mailbox index from disk. Use only to reset a corrupted or schema-incompatible index. After clearing, call sync_emails to rebuild. Irreversible — all indexed metadata and search history is lost. Does NOT clear in-memory caches — use clear_cache for that.
create_folderwriteCreate a new mailbox folder via IMAP. Use
create_labelwriteCreate a Proton label (IMAP folder under Labels/ namespace). Idempotent — safe to call if the label may already exist. For folder creation use create_folder with a Folders/ prefix.
create_templatewriteSave a reusable email template. Subject and body may contain {{variable}} placeholders (e.g. {{firstName}}), auto-detected and stored on the template. Fails if a template with the same name already exists — delete it first to replace it.
delete_draftdestructivePermanently delete a locally saved draft from SQLite. Use to discard a draft you no longer need. Does NOT remove a matching draft from the Proton Drafts IMAP folder — that requires a separate mailbox action. Irreversible; requires confirmed:true when PROTONMAIL_CONFIRM_DESTRUCTIVE is enabled.
delete_emaildestructivePermanently delete a single email via IMAP expunge. Use only when certain the message is no longer needed. Prefer trash_email if recovery may be required. Prefer bulk_delete to delete multiple emails at once. Prefer delete_thread to delete all messages in a conversation. Irreversible.
delete_folderdestructiveDelete an empty mailbox folder via IMAP. The folder must contain no messages — move or trash all messages first. Do NOT delete system folders (INBOX, Sent, Trash, Archive, Spam). Irreversible; messages already removed cannot be recovered this way.
delete_labeldestructiveDelete a Proton label (IMAP folder under Labels/ namespace). Deletes the label itself, not the messages — they remain in their other folders/labels. Irreversible. For deleting a folder use delete_folder with a Folders/ prefix.
delete_templatedestructiveDelete a saved email template. Irreversible; requires confirmed:true when PROTONMAIL_CONFIRM_DESTRUCTIVE is enabled.
delete_threaddestructiveDelete all messages in a thread, identified by RFC 5322 Message-ID header. permanent:true permanently expunges; false moves to Trash. Use when you have the raw Message-ID. Prefer apply_thread_action with action
empty_folderdestructivePermanently delete ALL messages in a folder at once. Prefer bulk_delete when removing a subset of messages rather than everything in the folder. Use only when the goal is to clear an entire folder (e.g. emptying Trash or Spam). Only available when PROTONMAIL_ALLOW_EMPTY_FOLDER=true. Irreversible.
export_emailwriteSave a message
flag_threaddestructiveAdd or remove IMAP flags across all messages in a thread, identified by RFC 5322 Message-ID header. Use when you have the raw Message-ID and want to flag an entire conversation at once. Prefer apply_thread_action with action
forward_emailreadImmediately forward an existing email to new recipients, preserving original attachments and prepending an optional note. Use when you have an emailId and want to re-route the message without review. Prefer create_forward_draft to stage a forward for review first. Requires PROTONMAIL_ALLOW_SEND.
get_audit_logswriteReturn recent entries from the persistent on-disk audit log of all write operations performed by this server. Use to review what mutations (sends, moves, deletes, draft operations) were executed across sessions. Prefer get_logs for debugging in-session behavior and transient connection errors.
get_connection_statusreadCheck whether Proton Bridge SMTP and IMAP are reachable and return authentication status for each. Use to diagnose connectivity before sending or syncing, or when tools return connection errors. Returns individual pass/fail for each protocol, plus this server
get_emails_by_idsreadFetch full content for multiple emails by composite id in one call (max 25). Use to read a batch of specific messages from a prior get_emails/search_emails/search_indexed_emails result without one get_email_by_id round trip per message. One failed id does not fail the whole batch — check each result
get_follow_up_candidatesreadReturn threads that appear overdue for follow-up based on age and pending-on state. Use when looking for outbound messages you sent that haven
get_inbox_digestreadReturn a structured inbox summary: unread counts, top actionable threads, and overdue threads where a reply is pending from you. Use as the starting point for an inbox review session to get an at-a-glance picture. Prefer get_actionable_threads for a deeper, filterable list of threads needing action.
get_index_statuswriteReturn metadata about the local SQLite email index: row count, last sync timestamp, index schema version, and per-folder coverage. Use to verify the index is fresh and complete before querying it with search_indexed_emails or get_threads. If the index is empty or stale, call sync_emails first.
get_labelsreadReturn normalized Proton folders and labels from the local mailbox index, including message counts per label. Use to enumerate available labels before filtering with search_indexed_emails or get_threads. Prefer get_folders for live IMAP folder counts when the index may be stale.
get_runtime_statusreadReturn the server
get_templatereadGet a single saved email template by id.
get_thread_by_idreadFetch the complete normalized thread record from the local index, including all messages, participants, labels, and full metadata. Use when you need all messages in a thread. Prefer get_thread_brief for a summarized quick view that avoids returning the full message list.
get_unsubscribe_inforeadRead the List-Unsubscribe header of a message and report how to unsubscribe from it — a mailto address, an https link, or both. Does not take any action. Use before unsubscribe_sender to see what
import_emailwriteImport a raw RFC822 message (.eml content) into a folder via IMAP APPEND. Use to restore a backed-up message or migrate mail from another provider
list_accountsreadList every configured Proton address (the primary Bridge login plus any additional addresses from PROTONMAIL_ACCOUNTS_JSON), each with its own IMAP/SMTP connection status and local index freshness. Use to see which accounts this server is managing, and each account
list_remote_draftsreadList draft messages currently stored in the Proton Drafts IMAP folder on the server. Use to see drafts created via Proton webmail or mobile app that have not been synced locally. Prefer list_drafts to see drafts managed by this server. Requires an active IMAP connection.
list_snoozedreadList every snoozed email, including its id, status, and wakeAt — use this to rediscover the id needed for cancel_snooze if it was lost with the conversation.
list_templatesreadList all saved email templates.
mark_email_readreadMark a single email as read or unread by setting the IMAP Seen flag. Use for individual triage or to reset read state. Prefer batch_email_action with action
move_emailwriteMove a single email to any specified mailbox folder. Use when routing a message to a custom folder. Prefer archive_email to move to the standard Archive folder, or trash_email to move to Trash. Use get_folders first to confirm the target folder path.
move_threadwriteMove all messages in a thread to a destination folder, identified by its RFC 5322 Message-ID header. Use when you have the raw Message-ID (e.g. from email headers) and want to move the full conversation. Prefer apply_thread_action with action
prepare_meeting_contextreadFetch recent threads and communication history for a person or company domain to prepare for a meeting or call. Use before a scheduled meeting to surface relevant recent correspondence. Provide at least one of person (name or email fragment) or domain. Returns matched threads sorted by recency.
rename_folderwriteRename or move a mailbox folder to a new IMAP path. Existing messages are preserved in place. Do NOT rename system folders (INBOX, Sent, Trash, Archive, Spam). Refreshes the local folder cache after the operation.
rename_labelwriteRename a Proton label (IMAP folder under Labels/ namespace). Messages keep the label, just under the new name. For renaming a folder use rename_folder with a Folders/ prefix.
render_templatereadRender a saved template
restore_emailwriteMove an email from Trash back to INBOX or to a specified folder. Use to undo a trash_email operation. Does not work on permanently deleted messages — only messages currently in Trash can be restored.
run_doctorwriteRun a comprehensive production health check covering SMTP auth, IMAP auth, optional IMAP IDLE probe, SQLite index integrity, sync-failed drafts, runtime policy validation, and what this server can/cannot do (capabilities). Also reports this server
schedule_draftwriteQueue a saved draft to send at a future time instead of immediately. IMPORTANT: this only fires while this MCP server process stays running (it
search_emailsreadSearch emails via live IMAP filters, across ALL configured accounts by default (accounts are queried one at a time; pass
search_indexed_emailsreadSearch the local SQLite mailbox index (of ALL configured accounts by default; pass
star_emailreadStar or unstar a single email using the IMAP Flagged flag. Use to bookmark an important message for later follow-up. Prefer batch_email_action with action
sync_draft_to_remotedestructiveForce-push a locally saved draft to the Proton Drafts IMAP folder and return the remote UID. Use when a draft was created with syncToRemote:false or when the automatic sync failed. Do NOT use this if PROTONMAIL_ALLOW_REMOTE_DRAFT_SYNC is false — the call will be rejected.
sync_folderswriteRefresh the in-memory folder list from the IMAP server and return the updated list. Use when folders have been created, renamed, or deleted externally (e.g. via Proton webmail) and get_folders is returning stale data. Prefer get_folders for a read-only view that does not force a refresh.
top_sendersreadReturn a frequency table of the top senders in a folder over a date range. Keyed on the sender address, not the display name, so display-name spoofing does not conflate different senders. Use for inbox analytics, unsubscribe triage, and contact discovery.
trash_emailwriteMove a single email to the Trash folder. Messages in Trash can be recovered with restore_email. Use instead of delete_email when you may want to recover the message later. Prefer batch_email_action with action
unsubscribe_senderwriteExecute the mailto: variant of a message
update_draftwriteUpdate an existing locally saved draft
update_message_labelsdestructiveAdd or remove Proton labels on a single message without moving it. Prefer bulk_update_labels to apply label changes across multiple messages. Labels live under the Labels/ namespace (e.g.
wait_for_mailbox_changesreadOpen an IMAP IDLE session and block until a mailbox change event arrives or the timeout expires. Use to detect real-time inbox activity without polling. Returns whether a change was observed. Always returns within timeoutSeconds plus a few seconds
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (17)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/services/simple-imap-service.ts:852
tls: this.shouldRelaxTlsVerification() ? { rejectUnauthorized: false } : undefined,
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/services/smtp-service.ts:239
tls: isLocalhost ? { rejectUnauthorized: false } : undefined,
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
bulk_update_labels, cancel_reply_reminder, clear_cache, clear_index, delete_draft, delete_email, delete_folder, delete_label, delete_template, delete_thread, empty_folder, flag_thread, sync_draft_to_r
Why it matters. 14 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/attachment-handling.test.mjs:23
assert.match(sanitizeFileName("../../etc/passwd"), /^_+etc_passwd$/, "no dots or separators survive");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/helpers/close-indexes.mjs:1
import { LocalIndexService } from "../../dist/services/local-index-service.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/helpers/crash-child.mjs:7
import { DraftStoreService } from "../../dist/services/draft-store-service.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/helpers/crash-child.mjs:8
import { DeliveryQueueService } from "../../dist/services/delivery-queue-service.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/helpers/crash-child.mjs:9
import { withFileLock } from "../../dist/utils/file-lock.js";
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
test/installer-config.test.mjs:87
const { configPath } = await configFixture('{"theme":"dark"}');
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, better-sqlite3, imapflow, mailparser, nodemailer, sanitize-html, turndown, @types/better-sqlite3
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:27
Give Claude Desktop (or Cline, or any MCP client) full access to your Proton Mail inbox: read, search, send, draft, triage threads, manage folders, save attachments, and more — 100 MCP tools in total.
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:35
1. **Install and sign in to [Proton Mail Bridge](https://proton.me/mail/bridge)**, and leave it running. In the Bridge app, open your account and copy the **Bridge password** (it is not your Proton pa
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.override · CWE-94, CWE-1427
CHANGELOG.md:1141
- Investigated `get_inbox_digest`, `find_document_threads`, and `prepare_meeting_context` for a prompt-injection surface (these tools feed raw, unfiltered email content — including from strangers — in
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:29
> **Using Proton Drive too?** See [**proton-drive-mcp**](https://github.com/googlarz/proton-drive-mcp), the companion MCP server and CLI for Proton Drive (upload, download, share and manage your encry
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:67
If you use Claude Desktop with the default Anthropic API, conversation content (including email snippets) is sent to Anthropic per their [privacy policy](https://www.anthropic.com/privacy). If you sel
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:661
- **Each `update_draft` uploads the whole draft to the Drafts folder** (the full message, attachment bytes included — about 1.4 MB of MIME for a 1 MiB attachment) unless you pass `syncToRemote:false`.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:714
- **[proton-drive-mcp](https://github.com/googlarz/proton-drive-mcp)** — the companion MCP server and CLI for **Proton Drive**: upload, download, share and manage your end-to-end encrypted files from
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha a27d1c5fe30afull audit observations/trust-audit/mcp-server/googlarz__proton-mail-bridge-client.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08a27d1c5fe30aBLOCKD69first audit
06

Questions

What is the Proton Mail Bridge Client MCP server?

Local-first Proton Mail MCP server and CLI via Proton Bridge. Search, draft, send and organize mail from Claude Desktop, Claude Code or any MCP client. 96 tools, read-only and send-to-self modes.

What tools does Proton Mail Bridge Client expose?

60 in total: 25 read-only, 21 that write, and 14 that can delete or overwrite (bulk_update_labels, cancel_reply_reminder, clear_cache, clear_index, delete_draft). Every one is listed on this page with its risk.

Is Proton Mail Bridge Client safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 14 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Proton Mail Bridge Client need?

It reads PROTONMAIL_IMAP_PASSWORD, PROTONMAIL_PASSWORD, PROTONMAIL_PASSWORD_COMMAND and PROTONMAIL_PASSWORD_FILE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Proton Mail Bridge Client run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as proton-mail-bridge-client at 2.8.1.

How current is this page?

The grade is for one exact copy of the source (a27d1c5fe30a), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement