# io.github.R1ghtHereWaiting/engagelab-email

> Send, receive, monitor and reply to email from AI agents with threaded inbox context.

- name: io.github.R1ghtHereWaiting/engagelab-email
- version: 0.1.2
- connection class: L0 (run_local_package)
- trust: 81/100
- quality: –/100 (not scored)
- owner: not claimed
- descriptor: https://api.protogrid.dev/v1/servers/io.github.R1ghtHereWaiting%2Fengagelab-email
- tools: https://api.protogrid.dev/v1/servers/io.github.R1ghtHereWaiting%2Fengagelab-email/tools

**Runs on your machine: something must execute the package.** Only local packages are published (npm, PyPI, OCI, …). The registry never executes them, so tools are unknown until you run it.

## Connection (mcpServers)

```json
{
  "mcpServers": {
    "engagelab-email": {
      "command": "npx",
      "args": [
        "-y",
        "@engagelabemail/mcp@0.1.2"
      ],
      "env": {
        "ENGAGELAB_EMAIL_SECRET_KEY": "${ENGAGELAB_EMAIL_SECRET_KEY}"
      }
    }
  }
}
```

Placeholders to fill: `${ENGAGELAB_EMAIL_SECRET_KEY}`.

## Trust

- hygiene: 100
- liveness: n/a
- freshness: 85
- provenance: 65
- drivers: +repository ~liveness-unmeasured ~updated-39d-ago
- Derived from observable signals (official registry feed and our own credential-free probes); no code audit performed.

## Quality –/100 (not scored)

Not scored: fewer than three checks apply, usually because no remote answered a credential-free probe or the server is a local package.

### protocol: n/a (weight 25)

- n/a `protocol.modern`, `protocol.stateless`, `protocol.transport`, `protocol.list_ttl`: no remote answered a protocol handshake (not probed yet, unreachable, or local-only)

### authorization: n/a (weight 15)

- n/a `auth.prm`, `auth.as_metadata`, `auth.cimd`: no remote uses OAuth
- n/a `auth.secret_in_url`: no templated URL

### tool hygiene: n/a (weight 30)

- n/a `tools.descriptions`, `tools.description_length`, `tools.schemas`, `tools.annotations`, `tools.directory_hints`, `tools.token_cost`, `tools.api_dump`: tool list unknown (behind auth, not probed, or empty)

### stability: n/a (weight 15)

- n/a `stability.changes`, `stability.rug_pull`: tool list unknown

### dependencies: 67 (weight 15)

- pass `deps.known_vulns`: no known advisory in 98 resolved packages
- fail `deps.mcp_sdk_version`: @modelcontextprotocol/sdk 1.30.1 has 1 known advisory (GHSA-6qxp-vccf-f47h); update @modelcontextprotocol/sdk to 1.31.0 or later
- pass `deps.resolvable`: @engagelabemail/mcp@0.1.2 resolved: 98 packages

- tools: unknown
- badge: [![protogrid quality](https://protogrid.dev/badge/io.github.R1ghtHereWaiting/engagelab-email.svg)](https://protogrid.dev/servers/io.github.R1ghtHereWaiting/engagelab-email)
- Checks run on what our credential-free, read-only probes observe; tools are never called and no code audit is performed.

### Tool changes

_No tool definition changes recorded._

## Dependencies

- npm @engagelabemail/mcp@0.1.2: resolved, 97 dependencies, MCP SDK @modelcontextprotocol/sdk 1.30.1
  - GHSA-6qxp-vccf-f47h (high) in `` @modelcontextprotocol/sdk@1.30.1 ``, direct, fixed in `` 1.31.0 ``, advisory summary: "MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server" https://osv.dev/vulnerability/GHSA-6qxp-vccf-f47h

Dependency graphs from deps.dev; advisories from OSV.dev, including the GitHub Advisory Database and the PyPI Advisory Database; all CC BY 4.0.

## Remotes

_none_

## Packages

- npm @engagelabemail/mcp@0.1.2 secrets: ENGAGELAB_EMAIL_SECRET_KEY

## Tools (0)

_none observed_
