Atlas / MCP servers / shuakami / Mail

MailCAUTION

mcp/shuakami/mail

📧 MCP Mail Tool - AI-powered email management tool | 基于 MCP 的智能邮件管理工具

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
17 17r · 0w · 0d
Transport
stdio
License
—
Stars
49
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://opensource.org/licenses/ISC) [](https://nodejs.org/) [](https://www.typescriptlang.org/) [](https://github.com/shuakami/mcp-mail) [](https://smithery.ai/server/@shuakami/mcp-mail)

English Version (README-EN.md)

这是什么

这是一个基于 MCP (Model Context Protocol) 的邮件工具,它能让 AI 模型通过标准化接口访问电子邮件服务。

简单来说,它让 AI 助手能够执行各种邮件操作,如发送邮件、阅读收件箱、处理附件等,无需用户手动输入复杂的API调用或切换到邮件客户端。

支持的功能 (点击展开)

  • 邮件发送:普通文本邮件、HTML邮件、带附件邮件、群发邮件
  • 邮件接收与查询:获取文件夹列表、列出邮件、高级搜索、获取邮件详情
  • 邮件管理:标记已读/未读、删除邮件、移动邮件
  • 附件管理:查看附件列表、下载附件、查看附件内容
  • 联系人管理:获取联系人列表、搜索联系人

功能特点 (点击展开)

以下是 Mail MCP 工具的一些核心特点:

  • 高级搜索功能:支持多文件夹、关键词、日期范围、发件人、收件人等复杂条件搜索
  • 智能联系人管理:自动从邮件历史中提取联系人信息,包括联系频率分析
  • 内容范围控制:可以分段查看大型邮件,避免加载过多内容
  • 多种邮件格式:支持纯文本和HTML格式邮件的发送和显示
  • 附件处理能力:智能识别附件类型,支持文本、图片等不同类型的附件预览
  • 安全可靠:本地处理所有邮件操作,不通过第三方服务器转发敏感信息

通过简单的自然语言指令,AI 可以帮助你完成上述所有操作,无需手动编写API调用或在邮件客户端中执行复杂操作。

快速上手

0. 环境准备

如果你之前没有使用过 Node.js (点击展开)

  1. 安装 Node.js 和 npm
  2. 访问 Node.js 官网
  3. 下载并安装 LTS(长期支持)版本
  4. 安装时选择默认选项即可,安装包会同时安装 Node.js 和 npm
  1. 验证安装
  2. 安装完成后,打开命令提示符(CMD)或 PowerShell
  3. 输入以下命令确认安装成功:
node --version
npm --version
  • 如果显示版本号,则表示安装成功
  1. 安装 Git(如果尚未安装)
  2. 访问 Git 官网
  3. 下载并安装 Git
  4. 安装时使用默认选项即可
  1. 安装 Python 3.11 或更高版本(必需)
  2. 访问 Python 官网
  3. 下载并安装 Python 3.11 或更高版本
  4. 重要:安装时必须勾选"Add Python to PATH"选项
  5. 安装完成后重启电脑,确保环境变量生效
Read from source at commit 287ac1da8c6bOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-mail --env IMAP_PASS=${IMAP_PASS} --env SMTP_PASS=${SMTP_PASS} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-mail": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "IMAP_PASS": "${IMAP_PASS}",
        "SMTP_PASS": "${SMTP_PASS}"
      }
    }
  }
}
03

Exposed tools (17)

17 read · 0 write · 0 destructive.

ToolRiskDescription
deleteEmailread
getAttachmentread
getContactsread
getEmailDetailread
listEmailsread
listFoldersread
markAsReadread
markAsUnreadread
markMultipleAsReadread
markMultipleAsUnreadread
moveEmailread
searchEmailsread
sendBulkMailread
sendHtmlMailread
sendMailread
sendSimpleMailread
waitForReplyread
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/tools/mail-service.ts:113
tlsOptions: { rejectUnauthorized: false },
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/node, dotenv, nodemailer, imap, mailparser, typescript, zod
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha 287ac1da8c6bfull audit observations/trust-audit/mcp-server/shuakami__mail.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08287ac1da8c6bCAUTIONB89first audit
06

Questions

What is the Mail MCP server?

📧 MCP Mail Tool - AI-powered email management tool | 基于 MCP 的智能邮件管理工具

What tools does Mail expose?

17 in total: 17 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Mail safe to connect to an agent?

With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Mail need?

It reads IMAP_PASS and SMTP_PASS from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Mail run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-mail at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (287ac1da8c6b), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement