A real inbox for AI agents: send, receive and thread email, behind a prompt-injection firewall.
Déduit des transports déclarés par cette annonce (stdio). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.
MAILS_API_KEYClé d’APIobligatoireYour mails.ai API key. Use an mk_test_ key to run against the sandbox or an mk_live_ key to send real mail. Free key at https://mails.ai
Déclaré par l’auteur dans le registre MCP officiel. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.
La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.
Lu dans le code que npm livre réellement, au moment de l’analyse. Le paquet n’a jamais été exécuté. Les outils enregistrés dynamiquement à l’exécution, ou cachés dans du code empaqueté ou minifié, peuvent passer inaperçus — c’est donc un plancher de la surface d’outils, pas un recensement complet.
mails.sendSend an email. `agent` is OPTIONAL: omit it and the workspace's single agent is used, or one is created for you (named from `from`) — so a first send needs no setup. Pass `agent` only when the workspace has several and you must say which. The reputation firewall runs on every send: an agent auto-su…Send an email. `agent` is OPTIONAL: omit it and the workspace's single agent is used, or one is created for you (named from `from`) — so a first send needs no setup. Pass `agent` only when the workspace has several and you must say which. The reputation firewall runs on every send: an agent auto-su…
Aucun schéma d’entrée n’a été publié pour cet outil.
mails.replyReply to a previously-received message. Sets In-Reply-To + Re: subject server-side.Reply to a previously-received message. Sets In-Reply-To + Re: subject server-side.
Aucun schéma d’entrée n’a été publié pour cet outil.
mails.forwardForward a message to new recipients.Forward a message to new recipients.
Aucun schéma d’entrée n’a été publié pour cet outil.
mails.list_threadsList threads (conversations) for the workspace or a specific agent.List threads (conversations) for the workspace or a specific agent.
Aucun schéma d’entrée n’a été publié pour cet outil.
mails.get_threadGet a full thread with all messages in chronological order.Get a full thread with all messages in chronological order.
Aucun schéma d’entrée n’a été publié pour cet outil.
mails.list_receivedList recently received messages.List recently received messages.
Aucun schéma d’entrée n’a été publié pour cet outil.
mails.get_receivedGet one received message including extracted reply text.Get one received message including extracted reply text.
Aucun schéma d’entrée n’a été publié pour cet outil.
mails.list_agentsList the agents in the workspace. Returns SENDABLE agents by default (status=live); archived agents cannot send, so they are excluded unless you ask for them. Pass status="all" to see archived ones too.List the agents in the workspace. Returns SENDABLE agents by default (status=live); archived agents cannot send, so they are excluded unless you ask for them. Pass status="all" to see archived ones too.
Aucun schéma d’entrée n’a été publié pour cet outil.
mails.create_agentCreate a new agent.Create a new agent.
Aucun schéma d’entrée n’a été publié pour cet outil.
mails.list_repliesList recent reply events (reply.received) for an agent.List recent reply events (reply.received) for an agent.
Aucun schéma d’entrée n’a été publié pour cet outil.
mails.list_messagesList recent cold/first-contact inbound (message.received) for an agent — senders that are NOT replying to one of your sends.List recent cold/first-contact inbound (message.received) for an agent — senders that are NOT replying to one of your sends.
Aucun schéma d’entrée n’a été publié pour cet outil.
mails.get_eventGet a specific inbound event by ID.Get a specific inbound event by ID.
Aucun schéma d’entrée n’a été publié pour cet outil.
mails.get_reputationGet an agent's sending-reputation health (0-1) + its 30-day bounce/complaint/reply counts. The firewall auto-suspends an agent that crosses a 0.3% complaint rate — well before the upstream provider's 0.5% line — so check this to catch an at-risk agent before it gets paused.Get an agent's sending-reputation health (0-1) + its 30-day bounce/complaint/reply counts. The firewall auto-suspends an agent that crosses a 0.3% complaint rate — well before the upstream provider's 0.5% line — so check this to catch an at-risk agent before it gets paused.
Aucun schéma d’entrée n’a été publié pour cet outil.
mails.check_suppressionCheck if an address is suppressed.Check if an address is suppressed.
Aucun schéma d’entrée n’a été publié pour cet outil.
mails.allowlist_addressOverride suppression for one address with a >=20 char attestation.Override suppression for one address with a >=20 char attestation.
Aucun schéma d’entrée n’a été publié pour cet outil.
mails.create_draftStage a draft. Optionally pass send_at to schedule.Stage a draft. Optionally pass send_at to schedule.
Aucun schéma d’entrée n’a été publié pour cet outil.
mails.send_draftSend a previously-created draft.Send a previously-created draft.
Aucun schéma d’entrée n’a été publié pour cet outil.
mails.get_usageGet the current billing period usage.Get the current billing period usage.
Aucun schéma d’entrée n’a été publié pour cet outil.
mails.meWho am I — returns the authenticated workspace, agent, tier, and API-key scopes. Call this first to confirm the connection is live.Who am I — returns the authenticated workspace, agent, tier, and API-key scopes. Call this first to confirm the connection is live.
Aucun schéma d’entrée n’a été publié pour cet outil.
mails.test_inboundAucune description publiéeCet outil n’a publié aucune description. Forge n’en invente pas.
19 outils sur 20 ont publié une description.
Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.
A real inbox for AI agents: send, receive and thread email, behind a prompt-injection firewall.
Les noms cliquables ouvrent l’index Forge de toutes les entrées observées exposant cet outil. Parcourir tous les outils indexés.
L'exploration s'est arrêtée à la limite de profondeur 4. Tout ce qui se trouve en dessous n'a jamais été résolu.
L'exploration s'est arrêtée à la limite de 60 paquets. Le reste de l'arbre n'a jamais été résolu.
36 autres paquets résolus ne sont pas dessinés ici (limite d'affichage : 24). Toute dépendance porteuse d'un avis de sécurité est dessinée quelle que soit la limite. Inventaire complet (SBOM CycloneDX)
54 dépendances déclarées ne sont jamais arrivées dans l'arbre. Elles manquent à la résolution de Forge, pas au paquet.
+42 de plus non listées. Les comptes par motif ci-dessus les couvrent toutes.
Non suivies : peerDependencies. Cet arbre ne couvre que les dépendances d'exécution ; ce qu'elles entraînent n'a jamais été résolu.