Search / io.github.infoinlet-marketplace/mcp-email
mcp-email
L0 · runs locallyEmail for AI agents — read inbox (IMAP), search, and send (SMTP).
v0.1.1 · active · repository · descriptor JSON · versions
Search / io.github.infoinlet-marketplace/mcp-email
Email for AI agents — read inbox (IMAP), search, and send (SMTP).
v0.1.1 · active · repository · descriptor JSON · versions
{
"mcpServers": {
"mcp-email": {
"command": "npx",
"args": [
"-y",
"@infoinlet/[email protected]"
]
}
}
}claude mcp add mcp-email -- npx -y @infoinlet/[email protected][mcp_servers.mcp-email]
command = "npx"
args = ["-y", "@infoinlet/[email protected]"]
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"mcp-email": {
"type": "local",
"command": [
"npx",
"-y",
"@infoinlet/[email protected]"
],
"enabled": true
}
}
}{
"mcpServers": {
"mcp-email": {
"command": "npx",
"args": [
"-y",
"@infoinlet/[email protected]"
]
}
},
"deeplink": "cursor://anysphere.cursor-deeplink/mcp/install?name=mcp-email&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIkBpbmZvaW5sZXQvbWNwLWVtYWlsQDAuMS4xIl19"
}{
"servers": {
"mcp-email": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@infoinlet/[email protected]"
]
}
}
}{
"mcpServers": {
"mcp-email": {
"command": "npx",
"args": [
"-y",
"@infoinlet/[email protected]"
]
}
}
}extensions:
"mcp-email":
enabled: true
name: "mcp-email"
type: stdio
cmd: "npx"
args:
- "-y"
- "@infoinlet/[email protected]"
timeout: 300
This is a local package: the command runs on your machine.
Not scored: fewer than three checks apply, usually because no remote answered a credential-free probe or the server is a local package.
protocol.modern, protocol.stateless, protocol.transport, protocol.list_ttlno remote answered a protocol handshake (not probed yet, unreachable, or local-only)auth.prm, auth.as_metadata, auth.cimdno remote uses OAuthauth.secret_in_urlno templated URLtools.descriptions, tools.description_length, tools.schemas, tools.annotations, tools.directory_hints, tools.token_cost, tools.api_dumptool list unknown (behind auth, not probed, or empty)stability.changes, stability.rug_pulltool list unknowndeps.known_vulns5 advisories to act on (malicious, or rated high or critical with a fix available): GHSA-2x7j-588g-ccc2 in [email protected] (direct, fixed in 9.1.0), GHSA-p6gq-j5cr-w38f in [email protected] (direct, fixed in 9.0.1), GHSA-r7g4-qg5f-qqm2 in [email protected] (direct, fixed in 8.0.8), ...; 10 more of lower severity or without a fixdeps.mcp_sdk_version@modelcontextprotocol/sdk 1.30.1 has 1 known advisory (GHSA-6qxp-vccf-f47h); update @modelcontextprotocol/sdk to 1.31.0 or laterdeps.resolvable@infoinlet/[email protected] resolved: 146 packagesNo tool definition changes recorded. A server's first observation is its baseline; later probes record what changes.
Checks run on what our credential-free, read-only probes observe; tools are never called and no code audit is performed. How it is computed.
+repository +namespace-matches-repo ~liveness-unmeasured ~updated-133d-ago -duplicate-repo(30 names)
Derived from observable signals (official registry feed and our own credential-free probes); no code audit performed. How it is computed.
@infoinlet/[email protected] npm145 dependencies, resolved · MCP SDK @modelcontextprotocol/sdk 1.30.1 · advisories checked 2026-10-09
| advisory | severity | package | fixed in |
|---|---|---|---|
| GHSA-6qxp-vccf-f47hMCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server | high | @modelcontextprotocol/[email protected]MCP SDK, direct | fixed in 1.31.0 |
| GHSA-2x7j-588g-ccc2Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list | high | [email protected]direct | fixed in 9.1.0 |
| GHSA-p6gq-j5cr-w38fNodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message | high | [email protected]direct | fixed in 9.0.1 |
| GHSA-r7g4-qg5f-qqm2Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception | high | [email protected]direct | fixed in 8.0.8 |
| GHSA-rcmh-qjqh-p98vNodemailer’s addressparser is vulnerable to DoS caused by recursive calls | high | [email protected]direct | fixed in 7.0.11 |
| GHSA-v53p-9fqp-m79jNodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service | high | [email protected]direct | fixed in 10.0.6 |
| GHSA-268h-hp4c-crq3Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection | moderate | [email protected]direct | fixed in 8.0.9 |
| GHSA-6vj9-mwq6-2f5vNodemailer: Process-global DNS cache reuses TLS `servername` across transports, enabling cross-tenant SMTP credential disclosure | moderate | [email protected]direct | fixed in 10.0.2 |
| GHSA-8m3c-c648-2xjjNodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature | moderate | [email protected]direct | fixed in 9.1.1 |
| GHSA-8vvx-rff5-p5rqNodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS | moderate | [email protected]direct | fixed in 10.0.2 |
6 more advisories in the dependencies endpoint.
Dependency graphs from deps.dev; advisories from OSV.dev, including the GitHub Advisory Database and the PyPI Advisory Database; all CC BY 4.0. The graph is what a clean install of this version resolves today; nothing was installed or run. How it is checked.
| package | registry | version | runtime | secrets |
|---|---|---|---|---|
@infoinlet/mcp-email | npm | 0.1.1 | – |
No tools observed. Local packages are never executed by the registry.
Schemas: list_tools.
29 other active names share this repository (showing 10): io.github.infoinlet-marketplace/mcp-browser-research, io.github.infoinlet-marketplace/mcp-calendar, io.github.infoinlet-marketplace/mcp-clickhouse, io.github.infoinlet-marketplace/mcp-codeaudit, io.github.infoinlet-marketplace/mcp-data, io.github.infoinlet-marketplace/mcp-elasticsearch, io.github.infoinlet-marketplace/mcp-fetch, io.github.infoinlet-marketplace/mcp-filesystem, io.github.infoinlet-marketplace/mcp-git, io.github.infoinlet-marketplace/mcp-github
{
"name": "io.github.infoinlet-marketplace/mcp-email",
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"version": "0.1.1",
"packages": [
{
"version": "0.1.1",
"transport": {
"type": "stdio"
},
"identifier": "@infoinlet/mcp-email",
"registryType": "npm"
}
],
"repository": {
"url": "https://github.com/infoinlet-marketplace/marketplace",
"source": "github",
"subfolder": "services/mcp-email"
},
"description": "Email for AI agents — read inbox (IMAP), search, and send (SMTP)."
}