@assistantmail/assistantmail-mcp

MCPattested
v1.3.1io.github.AssistantMailMITUpdated 21d agonpmGitHub

Agent email with allowlist and consent via AssistantMail.

Works in
ClaudeCursorCopilotGemini

Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Attested build
A verified provenance attestation binds this artifact to the listed repository. Nobody has claimed the listing yet — this proves where the code was built, not who stands behind it.
16Downloads/wk
21d agoLast update
Needs 1 credential before it runs
  • ASSISTANT_MAIL_API_KEYAPI keyrequired

    AssistantMail API key (amk_...). Required unless passed per-tool.

Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Package
Authorio.github.AssistantMail
LicenseMIT
Version1.3.1
Sourcenpm+mcp-registry
Trust Status
A
85/100Trusted
Listed in Forge index+10/10
Identity verified · attested build+20/20
Ed25519 publish signature+0/5
Included automatically when the publisher runs `forge publish`
Domain verification+0/5
Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
npm Trusted Publishing (Sigstore)+5/5
npm maintainer match+0/5
Publisher: add the verified GitHub login to the npm package's maintainers (npm owner add <login>)
CVE scan · clean+30/30
Static analysis · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusIdentity verified
PublisherUnverified
SignatureUnsigned
Domain
Provenance✓ Sigstore-verified · 73d5e34
Dependencies✓ 60 resolved+ · none vulnerable
Tool surface22 tools · 3 privileged
Security scan✓ Cleanv1.3.1 · 18d agoHow well does this scan work?
EvalsNone
IndexedSep 5, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

22 tools · 3 privileged
Statically extracted from the published packagev1.3.1 · 18d ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

assistantmail_healthReturns AssistantMail MCP server and API endpoint metadata.

Returns AssistantMail MCP server and API endpoint metadata.

No input schema was published for this tool.

assistantmail_get_meGets account profile and tier metadata for the authenticated account.

Gets account profile and tier metadata for the authenticated account.

No input schema was published for this tool.

assistantmail_get_inbound_policyGets inbound email policy settings for the authenticated account.

Gets inbound email policy settings for the authenticated account.

No input schema was published for this tool.

assistantmail_update_inbound_policyUpdates inbound email policy for the authenticated account.

Updates inbound email policy for the authenticated account.

No input schema was published for this tool.

assistantmail_create_mailboxCreates a mailbox for the authenticated account.

Creates a mailbox for the authenticated account.

No input schema was published for this tool.

assistantmail_list_mailboxesLists mailboxes accessible to the authenticated account.

Lists mailboxes accessible to the authenticated account.

No input schema was published for this tool.

assistantmail_get_mailboxGets mailbox metadata for a mailbox ID.

Gets mailbox metadata for a mailbox ID.

No input schema was published for this tool.

assistantmail_update_mailboxUpdates mailbox metadata (currently display name).

Updates mailbox metadata (currently display name).

No input schema was published for this tool.

assistantmail_delete_mailboxprivilegedDeletes a mailbox and all associated messages.

Deletes a mailbox and all associated messages.

No input schema was published for this tool.

assistantmail_list_messagesLists inbound and outbound messages for a mailbox.

Lists inbound and outbound messages for a mailbox.

No input schema was published for this tool.

assistantmail_get_messageGets a specific message for a mailbox, including hydrated text/html bodies when available.

Gets a specific message for a mailbox, including hydrated text/html bodies when available.

No input schema was published for this tool.

assistantmail_send_emailQueues an outbound email for a mailbox.

Queues an outbound email for a mailbox.

No input schema was published for this tool.

assistantmail_reply_messageReplies to an existing message in a mailbox thread.

Replies to an existing message in a mailbox thread.

No input schema was published for this tool.

assistantmail_delete_messagesprivilegedDeletes messages from a mailbox by IDs or deletes all messages.

Deletes messages from a mailbox by IDs or deletes all messages.

No input schema was published for this tool.

assistantmail_get_usageGets daily and monthly send quota usage for a mailbox.

Gets daily and monthly send quota usage for a mailbox.

No input schema was published for this tool.

assistantmail_list_recipientsLists approved/pending recipients for the authenticated account.

Lists approved/pending recipients for the authenticated account.

No input schema was published for this tool.

assistantmail_add_recipientAdds a recipient and sends a consent invitation when required.

Adds a recipient and sends a consent invitation when required.

No input schema was published for this tool.

assistantmail_remove_recipientprivilegedRemoves a recipient from the allowed recipient list.

Removes a recipient from the allowed recipient list.

No input schema was published for this tool.

assistantmail_send_email_referenceProvides the AssistantMail REST endpoint and required headers for email send requests.

Provides the AssistantMail REST endpoint and required headers for email send requests.

No input schema was published for this tool.

assistantmail_list_messages_referenceProvides the AssistantMail REST endpoint for listing messages (inbound and outbound) in a mailbox.

Provides the AssistantMail REST endpoint for listing messages (inbound and outbound) in a mailbox.

No input schema was published for this tool.

assistantmail_get_message_referenceProvides the AssistantMail REST endpoint for fetching a single message including its full body content.

Provides the AssistantMail REST endpoint for fetching a single message including its full body content.

No input schema was published for this tool.

assistantmail_get_usage_referenceProvides the AssistantMail REST endpoint for checking send quota usage for a mailbox.

Provides the AssistantMail REST endpoint for checking send quota usage for a mailbox.

No input schema was published for this tool.

22 of 22 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Agent email with allowlist and consent via AssistantMail.

Keywords
mcp
Alternatives
Comparing tool surfaces…

Dependency tree

What one Forge scan resolved from npm metadata on 2026-09-05 — observed resolution, not a publisher declaration.

60 packages resolved · 2 direct · none carrying advisories Resolution stops at depth 4 and 60 packages.

The crawl stopped at the depth-4 limit. Anything below that level was never resolved.

The crawl stopped at the 60-package limit. The rest of the tree was never resolved.

36 more resolved packages are not drawn here (display cap: 24). Every dependency carrying an advisory is drawn regardless of the cap. Full inventory (CycloneDX SBOM)

Declared but not resolved

53 declared dependencies never landed in the tree. They are missing from Forge's resolution, not from the package.

+41 more not listed. The counts by reason above cover all of them.

Not followed: peerDependencies. This tree covers runtime dependencies only, so anything those pull in was never resolved.