Atlas / MCP servers / wyattjoh / JMAP

JMAPSAFE

mcp/wyattjoh/jmap-1

A Model Context Protocol (MCP) server that provides tools for interacting with JMAP (JSON Meta Application Protocol) email servers. Built with Deno and using the jmap-jam client library.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
12 7r · 3w · 2d
Transport
stdio
License
MIT
Stars
176
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://jsr.io/@wyattjoh/jmap-mcp) [](https://jsr.io/@wyattjoh/jmap-mcp) [](https://jsr.io/@wyattjoh/jmap) [](https://jsr.io/@wyattjoh)

A Deno workspace containing a functional JMAP email client and a Model Context Protocol (MCP) server built on top of it. The client package uses jmap-jam for JMAP protocol access; the MCP package adapts those typed operations into tools.

Features

Email Management Tools

  • Search Emails: Search emails with text queries, sender/recipient filters,

date ranges, and keywords. All filters are AND'd together.

  • Get Emails: Retrieve specific emails by ID with configurable property

selection

  • Get Threads: Retrieve email threads (conversation chains)
  • Mark Emails: Mark emails as read/unread, flagged/unflagged
  • Move Emails: Move emails to one mailbox
  • Patch Email Mailboxes: Add or remove selected mailbox memberships while

preserving unspecified memberships

  • Delete Emails: Delete emails permanently

Mailbox Management

  • Get Mailboxes: List all mailboxes/folders with hierarchy support. Use this

to find mailbox IDs needed by other tools.

Incremental Sync

  • Get Email Changes: Get IDs of emails created, updated, or destroyed since

a previous state (state-based delta tracking)

  • Get Search Updates: Get additions/removals within a previous search query

since its last queryState

Email Composition

  • Send Email: Compose and send new emails with support for plain text and

HTML

  • Reply to Email: Reply to existing emails with automatic header handling

and reply-all support

Key Capabilities

  • Full JMAP RFC 8620/8621 compliance via jmap-jam
  • Comprehensive input validation with Zod schemas
  • P
Read from source at commit 772d00cd1bdbOBSERVED · 2026-10-06
02

Exposed tools (12)

7 read · 3 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
delete_emailsdestructiveDelete emails permanently. This action cannot be undone. Prefer move_emails to Trash mailbox for safer deletion — use this only when permanent deletion is explicitly requested.
get_email_changesreadGet IDs of emails created, updated, or destroyed since a previous state. Use the state string from a get_emails response. Supports optional auto-fetching of full email details. If the state is too old, falls back with an error suggesting a fresh search_emails call.
get_emailsreadGet specific emails by their IDs. Use the
get_mailboxesread
get_search_updatesreadGet changes within a previous search query since its last queryState. You MUST pass the same filter parameters as the original search_emails call. Returns added and removed email IDs relative to that search.
get_threadsreadGet email threads by their IDs. Thread IDs are available from get_emails responses (threadId property). Returns a list of email IDs in each thread — use get_emails on those IDs to fetch the actual email content.
mark_emailswriteMark emails as read/unread or flagged/unflagged. You can update multiple keywords at once.
move_emailswriteMove emails to a different mailbox. Requires a mailbox ID — use get_mailboxes first to find the target mailbox ID by name.
patch_email_mailboxesdestructiveAdd or remove mailbox memberships without changing unspecified memberships. Use this to apply multiple labels or archive an email while preserving other labels.
reply_to_emailreadReply to an existing email. Automatically sets correct To/CC, subject (Re: prefix), and threading headers (In-Reply-To, References). Use replyAll=true to include all original recipients. The identityId parameter is optional — if omitted, the server uses the default sending identity.
search_emailsreadSearch emails with filters (text, sender/recipient, dates, keywords). All filters are AND
send_emailwriteSend a new email. Requires either textBody or htmlBody (or both). The identityId parameter is optional — if omitted, the server uses the default sending identity.
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (5)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_emails, patch_email_mailboxes
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmodules
.gitmodules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-please-manifest.json
.release-please-manifest.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
AGENTS.md
AGENTS.md
Why it matters. link not followed
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/jmap-mcp/tests/tools/email_test.ts:5
import { registerEmailTools } from "../../src/tools/email.ts";

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 772d00cd1bdbfull audit observations/trust-audit/mcp-server/wyattjoh__jmap-1.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06772d00cd1bdbSAFEB89first audit
05

Questions

What is the JMAP MCP server?

A Model Context Protocol (MCP) server that provides tools for interacting with JMAP (JSON Meta Application Protocol) email servers. Built with Deno and using the jmap-jam client library.

What tools does JMAP expose?

12 in total: 7 read-only, 3 that write, and 2 that can delete or overwrite (delete_emails, patch_email_mailboxes). Every one is listed on this page with its risk.

Is JMAP safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does JMAP need?

No credential environment variables were found in its source, so it appears to need none.

How does JMAP run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (772d00cd1bdb), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement