Atlas / MCP servers / nikolausm / IMAP

IMAPCAUTION

mcp/nikolausm/imap-4

A powerful Model Context Protocol (MCP) server for IMAP email integration with Claude

Verdict
CAUTION
Grade
B
Trust score
87 /100
Exposed tools
40 22r · 10w · 8d
Transport
stdio
License
MIT
Stars
103
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A powerful Model Context Protocol (MCP) server that provides seamless IMAP email integration with secure account management and connection pooling.

Features

  • 🔐 Secure Account Management: Encrypted credential storage with AES-256 encryption
  • 🚀 Connection Pooling: Efficient IMAP connection management
  • 📧 Comprehensive Email Operations: Search, read, move, mark, delete, and bulk delete emails
  • ✉️ Email Sending: Send, reply, and forward emails via SMTP
  • 📁 Folder Management: List folders, check status, get unread counts
  • 🔄 Multiple Account Support: Manage multiple IMAP accounts simultaneously
  • 🛡️ Type-Safe: Built with TypeScript for reliability
  • 🌐 Web-Based Setup Wizard: Easy account configuration with provider presets
  • 📱 15+ Email Providers: Pre-configured settings for Gmail, Outlook, Yahoo, and more
  • 🔗 Auto SMTP Configuration: Automatic SMTP settings based on IMAP provider

Installation

Requires Node.js 22.12 or newer. Node 18 and 20 have both reached end-of-life, and several of this package's dependencies no longer support them. Check yours with node --version.

Run via npx (No Installation Required)

Once published to npm, you can run the server directly without cloning or building anything — npx downloads the prebuilt package and runs it:

npx -y imap-mcp-server

This is the easiest way to use the server in an MCP client (see Configuration for ready-to-paste npx configs).

Quick Install (Recommended)

macOS/Linux:

curl -fsSL https://raw.githubusercontent.com/nikolausm/imap-mcp-server/main/install.sh | bash

Windows (PowerShell as Administrator):

iwr -useb https://raw.githubusercontent.com/nikolausm/imap-mcp-server/main/install.ps1 | iex

Manual Installation

  1. Clone the repository:
git clone https://github.com/nikolausm/imap-mcp-server.git
cd imap-mcp-server
  1. Install dependencie
Read from source at commit 6ebae8af186dOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add imap-mcp-server -- npx -y [email protected]
03

Exposed tools (40)

22 read · 10 write · 8 destructive. Blast radius: 8 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
imap_add_accountwrite
imap_add_keywordwrite
imap_add_spam_domainwrite
imap_add_whitelist_domainwrite
imap_bulk_deletedestructive
imap_bulk_delete_by_searchdestructive
imap_check_spamread
imap_connectread
imap_create_folderwrite
imap_delete_by_domaindestructive
imap_delete_emaildestructive
imap_delete_spamdestructive
imap_disconnectread
imap_domain_statsread
imap_download_attachmentread
imap_find_email_by_message_idread
imap_find_thread_messagesread
imap_flag_emailread
imap_folder_statusread
imap_forward_emailread
imap_get_emailread
imap_get_latest_emailsread
imap_get_unread_countread
imap_list_accountsread
imap_list_foldersread
imap_list_spam_domainsread
imap_mark_as_readread
imap_mark_as_unreadread
imap_move_emailwrite
imap_remove_accountdestructive
imap_remove_keyworddestructive
imap_remove_spam_domaindestructive
imap_reply_to_emailread
imap_save_draftwrite
imap_search_emailsread
imap_send_emailwrite
imap_test_accountread
imap_unflag_emailread
imap_update_accountwrite
imap_upload_filewrite
04

Trust audit

CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (14)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/web-server-accounts.test.ts:10
const SECRET = 'imap-plaintext-secret';
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
imap_bulk_delete, imap_bulk_delete_by_search, imap_delete_by_domain, imap_delete_email, imap_delete_spam, imap_remove_account, imap_remove_keyword, imap_remove_spam_domain
Why it matters. 8 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/env-credentials.test.ts:98
const wizardEnvVarName = new Function('accountName', 'suffix', match![1]) as
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/web/server.ts:110
path.join(__dirname, '../../public'),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/email-tools-attachment-path-traversal.test.ts:49
filename: '../../../../../../tmp/imap-mcp-escape.txt',
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/email-tools-attachment-path-traversal.test.ts:56
filename: '../../../../../../tmp/imap-mcp-escape.txt',
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/web-server-accounts.test.ts:53
baseUrl = `http://127.0.0.1:${port}`;
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
tests/html-to-markdown.test.ts:80
const out = normalizeWhitespace('a\n\n\n\nb c   \n');
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, body-parser, chalk, commander, cors, dotenv, express, imapflow
Why it matters. 29 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
AGENTS.md:18
Credentials can be overridden at read time via environment variables keyed
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CHANGELOG.md:108
- Selective tool access via environment variables (Issue #87). `IMAP_MCP_READ_ONLY` (truthy: `1`/`true`/`yes`/`on`) registers only the safe, read-only subset — searching, reading, listing folders, unr
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:664
(`0700`/`0600`) so other local users cannot read the key or the credentials
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
SECURITY.md:16
anyone who can read both files can read your credentials.
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:38
curl -fsSL https://raw.githubusercontent.com/nikolausm/imap-mcp-server/main/install.sh | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 6ebae8af186dfull audit observations/trust-audit/mcp-server/nikolausm__imap-4.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-076ebae8af186dCAUTIONB87first audit
06

Questions

What is the IMAP MCP server?

A powerful Model Context Protocol (MCP) server for IMAP email integration with Claude

What tools does IMAP expose?

40 in total: 22 read-only, 10 that write, and 8 that can delete or overwrite (imap_bulk_delete, imap_bulk_delete_by_search, imap_delete_by_domain, imap_delete_email, imap_delete_spam). Every one is listed on this page with its risk.

Is IMAP safe to connect to an agent?

With care. The audit graded it B (87/100) and found 14 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 8 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does IMAP need?

It reads IMAP_MCP_ACCOUNT_ENV_MANAGED_IMAP_PASSWORD, IMAP_MCP_ACCOUNT_WORK_GMAIL_IMAP_PASSWORD, IMAP_MCP_ACCOUNT_WORK_GMAIL_SMTP_PASSWORD and IPQUALITYSCORE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does IMAP run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as imap-mcp-server at 2.1.0.

How current is this page?

The grade is for one exact copy of the source (6ebae8af186d), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement