Atlas / MCP servers / timecyber / Email

EmailBLOCK

mcp/timecyber/email-4

一个让AI轻松接管邮箱的MCP服务,基于 Model Context Protocol (MCP) 构建,支持在 MCP-X,Claude Desktop 等 MCP 客户端中使用。

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
7 6r · 1w · 0d
Transport
stdio
License
MIT
Stars
80
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://badge.fury.io/js/mcp-email) [](https://www.npmjs.com/package/mcp-email) [](https://opensource.org/licenses/MIT)

一个让AI轻松接管邮箱的通用MCP服务器,基于 Model Context Protocol (MCP) 构建,支持在 MCP-X、Claude Desktop 等 MCP 客户端中使用。

支持多种邮箱服务商自动配置:QQ邮箱、163邮箱、Gmail、Outlook、腾讯企业邮箱、网易企业邮箱、阿里云邮箱、新浪邮箱、搜狐邮箱等。

📦 快速安装

# npm 安装
npm install -g mcp-email

# 使用 npx 运行(推荐)
npx mcp-email

✨ 功能特性

  • 📤 邮件发送: 支持发送HTML和纯文本邮件
  • 👥 多收件人: 支持多个收件人、抄送、密送
  • 📎 附件支持: 支持文件附件和Base64编码内容
  • 🔧 动态配置: 支持运行时配置邮箱服务器
  • 🔍 连接测试: 内置SMTP服务器连接测试
  • 🛡️ 安全认证: 支持微信企业邮箱授权码认证
  • ⚡ 高性能: 优化的连接超时和重试机制

📚 详细配置指南

项目提供了详细的配置指南,包含各大邮箱服务商的配置说明:

📖 CONFIG_GUIDE.md - 完整配置指南,包含:

  • 📧 163邮箱详细配置教程
  • 🏢 微信企业邮箱配置指南
  • 🌐 QQ邮箱、Gmail等主流邮箱配置
  • 🛠️ 故障排除和常见问题解决

📋 系统要求

  • Node.js 16.x 或更高版本
  • 邮箱账号
  • MCP 客户端 (如 Claude Desktop)

🚀 快速开始

方式一:直接使用npm包(推荐)

1. 安装npm包

# 全局安装
npm install -g mcp-email

# 或本地安装
npm install mcp-email

2. 在MCP客户端中配置

MCP-X 配置示例:

{
"mcpServers": {
"universal-email": {
"command": "npx",
"args": ["mcp-email"],
"env": {
"EMAIL_USER": "[email protected]",
"EMAIL_PASSWORD": "your-password-or-auth-code",
"EMAIL_TYPE": "auto"
}
}
}
}

方式二:从源码安装

1. 克隆项目

git clone https://github.com/TimeCyber/email-mcp.git
cd email-mcp

2. 安装依赖

npm install

3. 配置 MCP 客户端(源码安装)

MCP-X 配置:

{
"mcpServers": {
"universal-email": {
"command": "node",
"args": ["F:\\path\\to\\email-mcp\\index.js"],
"env": {
"EMAIL_USER": "[email protected]",
"EMAIL_PASSWORD": "your-password-or-auth-code",
"EMAIL_TYPE": "auto"
}
}
}
}

企业邮箱配置:

{
"mcpSe
Read from source at commit c82fc291d137OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-email --env EMAIL_PASSWORD=${EMAIL_PASSWORD} --env WECHAT_EMAIL_PASSWORD=${WECHAT_EMAIL_PASSWORD} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-email": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "EMAIL_PASSWORD": "${EMAIL_PASSWORD}",
        "WECHAT_EMAIL_PASSWORD": "${WECHAT_EMAIL_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (7)

6 read · 1 write · 0 destructive.

ToolRiskDescription
configure_email_serverread手动配置邮箱服务器设置(高级用户使用)
get_email_contentread获取指定邮件的详细内容
get_recent_emailsread获取最近三天的邮件列表
list_supported_providersread列出支持的邮箱提供商
send_emailwrite发送邮件
setup_email_accountread设置邮箱账号(自动识别邮箱类型并配置服务器)
test_email_connectionread测试邮箱服务器连接
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (4)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
index.js:448
tlsOptions: { rejectUnauthorized: false }
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
index.js:474
tlsOptions: { rejectUnauthorized: false }
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
test-auto-config.js:115
password: 'your-enterprise-auth-code',  // 需要实际的企业邮箱授权码
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, dotenv, imap, mailparser, nodemailer, poplib, @types/node, @types/nodemailer
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha c82fc291d137full audit observations/trust-audit/mcp-server/timecyber__email-4.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08c82fc291d137BLOCKD69first audit
06

Questions

What is the Email MCP server?

一个让AI轻松接管邮箱的MCP服务,基于 Model Context Protocol (MCP) 构建,支持在 MCP-X,Claude Desktop 等 MCP 客户端中使用。

What tools does Email expose?

7 in total: 6 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Email safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Email need?

It reads EMAIL_PASSWORD and WECHAT_EMAIL_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Email run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-email at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (c82fc291d137), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement