MailCAUTION
📧 MCP Mail Tool - AI-powered email management tool | 基于 MCP 的智能邮件管理工具
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://opensource.org/licenses/ISC) [](https://nodejs.org/) [](https://www.typescriptlang.org/) [](https://github.com/shuakami/mcp-mail) [](https://smithery.ai/server/@shuakami/mcp-mail)
English Version (README-EN.md)
这是什么
这是一个基于 MCP (Model Context Protocol) 的邮件工具,它能让 AI 模型通过标准化接口访问电子邮件服务。
简单来说,它让 AI 助手能够执行各种邮件操作,如发送邮件、阅读收件箱、处理附件等,无需用户手动输入复杂的API调用或切换到邮件客户端。
支持的功能 (点击展开)
- 邮件发送:普通文本邮件、HTML邮件、带附件邮件、群发邮件
- 邮件接收与查询:获取文件夹列表、列出邮件、高级搜索、获取邮件详情
- 邮件管理:标记已读/未读、删除邮件、移动邮件
- 附件管理:查看附件列表、下载附件、查看附件内容
- 联系人管理:获取联系人列表、搜索联系人
功能特点 (点击展开)
以下是 Mail MCP 工具的一些核心特点:
- 高级搜索功能:支持多文件夹、关键词、日期范围、发件人、收件人等复杂条件搜索
- 智能联系人管理:自动从邮件历史中提取联系人信息,包括联系频率分析
- 内容范围控制:可以分段查看大型邮件,避免加载过多内容
- 多种邮件格式:支持纯文本和HTML格式邮件的发送和显示
- 附件处理能力:智能识别附件类型,支持文本、图片等不同类型的附件预览
- 安全可靠:本地处理所有邮件操作,不通过第三方服务器转发敏感信息
通过简单的自然语言指令,AI 可以帮助你完成上述所有操作,无需手动编写API调用或在邮件客户端中执行复杂操作。
快速上手
0. 环境准备
如果你之前没有使用过 Node.js (点击展开)
- 安装 Node.js 和 npm
- 访问 Node.js 官网
- 下载并安装 LTS(长期支持)版本
- 安装时选择默认选项即可,安装包会同时安装 Node.js 和 npm
- 验证安装
- 安装完成后,打开命令提示符(CMD)或 PowerShell
- 输入以下命令确认安装成功:
node --version npm --version
- 如果显示版本号,则表示安装成功
- 安装 Git(如果尚未安装)
- 访问 Git 官网
- 下载并安装 Git
- 安装时使用默认选项即可
- 安装 Python 3.11 或更高版本(必需)
- 访问 Python 官网
- 下载并安装 Python 3.11 或更高版本
- 重要:安装时必须勾选"Add Python to PATH"选项
- 安装完成后重启电脑,确保环境变量生效
287ac1da8c6bOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-mail --env IMAP_PASS=${IMAP_PASS} --env SMTP_PASS=${SMTP_PASS} -- npx -y [email protected]{
"mcpServers": {
"mcp-mail": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"IMAP_PASS": "${IMAP_PASS}",
"SMTP_PASS": "${SMTP_PASS}"
}
}
}
}Exposed tools (17)
17 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
deleteEmail | read | |
getAttachment | read | |
getContacts | read | |
getEmailDetail | read | |
listEmails | read | |
listFolders | read | |
markAsRead | read | |
markAsUnread | read | |
markMultipleAsRead | read | |
markMultipleAsUnread | read | |
moveEmail | read | |
searchEmails | read | |
sendBulkMail | read | |
sendHtmlMail | read | |
sendMail | read | |
sendSimpleMail | read | |
waitForReply | read |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
tlsOptions: { rejectUnauthorized: false },@modelcontextprotocol/sdk, @types/node, dotenv, nodemailer, imap, mailparser, typescript, zod
Gates applied: no_behavioural_pass, no_license.
287ac1da8c6bfull audit observations/trust-audit/mcp-server/shuakami__mail.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 287ac1da8c6b | CAUTION | B | 89 | first audit |
Questions
What is the Mail MCP server?
📧 MCP Mail Tool - AI-powered email management tool | 基于 MCP 的智能邮件管理工具
What tools does Mail expose?
17 in total: 17 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Mail safe to connect to an agent?
With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Mail need?
It reads IMAP_PASS and SMTP_PASS from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Mail run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-mail at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (287ac1da8c6b), read on 2026-10-08. The repository is watched and re-audited when it changes.