# mxprobe

Email verification for AI agents: send, hold or kill with the reason. Signup and credits by API.

- **Type:** MCP server
- **Trust:** 85/100 (A), scored on the package rubric
- **Verification:** verified (build provenance)
- **Version:** 0.2.6
- **Author:** dev.mxprobe
- **License:** MIT
- **npm:** mxprobe
- **Source:** https://github.com/andrewchmr/mxprobe
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

85/100 (A), scored on the package rubric
- Publisher verified: no
- Build provenance: verified attestation
- npm trusted publishing (OIDC): yes
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 21 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-14T18:35:48.848Z
- **Version scanned:** 0.2.4
- **CVEs:** none found by OSV at scan time

## Tools

5 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `verify_email`
- `verify_batch`
- `signup` — Sign up with an email address. Returns an API key with 100 free checks and saves it locally for the other tools. The key is also mailed to the address. One key 
- `balance` — How many hosted checks are left on the configured API key.
- `buy_credits` — Get a Stripe Checkout link for more hosted checks: 9 USD per 10,000, one payment, credits never expire. Open the link to pay; credits land on the key when Strip

## Install

**Verdict: install** — No blocking findings and no open coverage gaps — safe to install as configured.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"mxprobe\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"mxprobe\"\n      ],\n      \"env\": {\n        \"MXPROBE_API_KEY\": \"<YOUR_MXPROBE_API_KEY>\"\n      }\n    }\n  }\n}"
```
**Credentials it will ask for** (names only — Forge never holds a value):
- `MXPROBE_API_KEY` — Mxprobe API Key (optional)
Placeholders only. Forge never holds, brokers, or transmits a credential value — replace each <YOUR_NAME> in your own config file. Do not send a value back to Forge; no Forge endpoint accepts one.
- This entry needs 1 credential (0 required). The generated config carries placeholders, so it will fail in the editor rather than at runtime if they are left unset.

## Blast radius

Moderate blast radius — holds an api key; runs on your machine.
- Floor 23, ceiling 23 (tier: moderate)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/mxprobe
- Install plan: https://forgeregistry.com/api/v1/packages/mxprobe/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/mxprobe
- HTML page: https://forgeregistry.com/registry/mxprobe
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
