# io.github.infoinlet-marketplace/mcp-email

> Email for AI agents — read inbox (IMAP), search, and send (SMTP).

- name: io.github.infoinlet-marketplace/mcp-email
- version: 0.1.1
- connection class: L0 (run_local_package)
- trust: 70/100 flags: duplicate-repo
- quality: –/100 (not scored)
- owner: not claimed
- descriptor: https://api.protogrid.dev/v1/servers/io.github.infoinlet-marketplace%2Fmcp-email
- tools: https://api.protogrid.dev/v1/servers/io.github.infoinlet-marketplace%2Fmcp-email/tools

**Runs on your machine: something must execute the package.** Only local packages are published (npm, PyPI, OCI, …). The registry never executes them, so tools are unknown until you run it.

## Connection (mcpServers)

```json
{
  "mcpServers": {
    "mcp-email": {
      "command": "npx",
      "args": [
        "-y",
        "@infoinlet/mcp-email@0.1.1"
      ]
    }
  }
}
```


## Trust

- hygiene: 60
- liveness: n/a
- freshness: 65
- provenance: 80
- drivers: +repository +namespace-matches-repo ~liveness-unmeasured ~updated-134d-ago -duplicate-repo(30 names)
- Derived from observable signals (official registry feed and our own credential-free probes); no code audit performed.

## Quality –/100 (not scored)

Not scored: fewer than three checks apply, usually because no remote answered a credential-free probe or the server is a local package.

### protocol: n/a (weight 25)

- n/a `protocol.modern`, `protocol.stateless`, `protocol.transport`, `protocol.list_ttl`: no remote answered a protocol handshake (not probed yet, unreachable, or local-only)

### authorization: n/a (weight 15)

- n/a `auth.prm`, `auth.as_metadata`, `auth.cimd`: no remote uses OAuth
- n/a `auth.secret_in_url`: no templated URL

### tool hygiene: n/a (weight 30)

- n/a `tools.descriptions`, `tools.description_length`, `tools.schemas`, `tools.annotations`, `tools.directory_hints`, `tools.token_cost`, `tools.api_dump`: tool list unknown (behind auth, not probed, or empty)

### stability: n/a (weight 15)

- n/a `stability.changes`, `stability.rug_pull`: tool list unknown

### dependencies: 33 (weight 15)

- fail `deps.known_vulns`: 5 advisories to act on (malicious, or rated high or critical with a fix available): GHSA-2x7j-588g-ccc2 in nodemailer@6.10.1 (direct, fixed in 9.1.0), GHSA-p6gq-j5cr-w38f in nodemailer@6.10.1 (direct, fixed in 9.0.1), GHSA-r7g4-qg5f-qqm2 in nodemailer@6.10.1 (direct, fixed in 8.0.8), ...; 10 more of lower severity or without a fix
- fail `deps.mcp_sdk_version`: @modelcontextprotocol/sdk 1.30.1 has 1 known advisory (GHSA-6qxp-vccf-f47h); update @modelcontextprotocol/sdk to 1.31.0 or later
- pass `deps.resolvable`: @infoinlet/mcp-email@0.1.1 resolved: 146 packages

- tools: unknown
- badge: [![protogrid quality](https://protogrid.dev/badge/io.github.infoinlet-marketplace/mcp-email.svg)](https://protogrid.dev/servers/io.github.infoinlet-marketplace/mcp-email)
- Checks run on what our credential-free, read-only probes observe; tools are never called and no code audit is performed.

### Tool changes

_No tool definition changes recorded._

## Dependencies

- npm @infoinlet/mcp-email@0.1.1: resolved, 145 dependencies, MCP SDK @modelcontextprotocol/sdk 1.30.1
  - GHSA-6qxp-vccf-f47h (high) in `` @modelcontextprotocol/sdk@1.30.1 ``, direct, fixed in `` 1.31.0 ``, advisory summary: "MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server" https://osv.dev/vulnerability/GHSA-6qxp-vccf-f47h
  - GHSA-2x7j-588g-ccc2 (high) in `` nodemailer@6.10.1 ``, direct, fixed in `` 9.1.0 ``, advisory summary: "Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list" https://osv.dev/vulnerability/GHSA-2x7j-588g-ccc2
  - GHSA-p6gq-j5cr-w38f (high) in `` nodemailer@6.10.1 ``, direct, fixed in `` 9.0.1 ``, advisory summary: "Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message" https://osv.dev/vulnerability/GHSA-p6gq-j5cr-w38f
  - GHSA-r7g4-qg5f-qqm2 (high) in `` nodemailer@6.10.1 ``, direct, fixed in `` 8.0.8 ``, advisory summary: "Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception" https://osv.dev/vulnerability/GHSA-r7g4-qg5f-qqm2
  - GHSA-rcmh-qjqh-p98v (high) in `` nodemailer@6.10.1 ``, direct, fixed in `` 7.0.11 ``, advisory summary: "Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls" https://osv.dev/vulnerability/GHSA-rcmh-qjqh-p98v
  - GHSA-v53p-9fqp-m79j (high) in `` nodemailer@6.10.1 ``, direct, fixed in `` 10.0.6 ``, advisory summary: "Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service" https://osv.dev/vulnerability/GHSA-v53p-9fqp-m79j
  - GHSA-268h-hp4c-crq3 (moderate) in `` nodemailer@6.10.1 ``, direct, fixed in `` 8.0.9 ``, advisory summary: "Nodemailer: CRLF injection in Nodemailer List-\* header comments allows arbitrary message header injection" https://osv.dev/vulnerability/GHSA-268h-hp4c-crq3
  - GHSA-6vj9-mwq6-2f5v (moderate) in `` nodemailer@6.10.1 ``, direct, fixed in `` 10.0.2 ``, advisory summary: "Nodemailer: Process-global DNS cache reuses TLS \`servername\` across transports, enabling cross-tenant SMTP credential disclosure" https://osv.dev/vulnerability/GHSA-6vj9-mwq6-2f5v
  - GHSA-8m3c-c648-2xjj (moderate) in `` nodemailer@6.10.1 ``, direct, fixed in `` 9.1.1 ``, advisory summary: "Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature" https://osv.dev/vulnerability/GHSA-8m3c-c648-2xjj
  - GHSA-8vvx-rff5-p5rq (moderate) in `` nodemailer@6.10.1 ``, direct, fixed in `` 10.0.2 ``, advisory summary: "Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS" https://osv.dev/vulnerability/GHSA-8vvx-rff5-p5rq
  - GHSA-cc9r-2j5m-2m83 (moderate) in `` nodemailer@6.10.1 ``, direct, fixed in `` 9.1.0 ``, advisory summary: "Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain" https://osv.dev/vulnerability/GHSA-cc9r-2j5m-2m83
  - GHSA-mm7p-fcc7-pg87 (moderate) in `` nodemailer@6.10.1 ``, direct, fixed in `` 7.0.7 ``, advisory summary: "Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict" https://osv.dev/vulnerability/GHSA-mm7p-fcc7-pg87
  - GHSA-vvjj-xcjg-gr5g (moderate) in `` nodemailer@6.10.1 ``, direct, fixed in `` 8.0.5 ``, advisory summary: "Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)" https://osv.dev/vulnerability/GHSA-vvjj-xcjg-gr5g
  - GHSA-wmmp-3585-3rmp (moderate) in `` nodemailer@6.10.1 ``, direct, fixed in `` 9.1.0 ``, advisory summary: "Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain" https://osv.dev/vulnerability/GHSA-wmmp-3585-3rmp
  - GHSA-wqvq-jvpq-h66f (moderate) in `` nodemailer@6.10.1 ``, direct, fixed in `` 8.0.9 ``, advisory summary: "Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization" https://osv.dev/vulnerability/GHSA-wqvq-jvpq-h66f
  - GHSA-c7w3-x93f-qmm8 (low) in `` nodemailer@6.10.1 ``, direct, fixed in `` 8.0.4 ``, advisory summary: "Nodemailer has SMTP command injection due to unsanitized \`envelope.size\` parameter" https://osv.dev/vulnerability/GHSA-c7w3-x93f-qmm8

Dependency graphs from deps.dev; advisories from OSV.dev, including the GitHub Advisory Database and the PyPI Advisory Database; all CC BY 4.0.

## Remotes

_none_

## Packages

- npm @infoinlet/mcp-email@0.1.1

## Tools (0)

_none observed_
