agent-notify
Let Claude, ChatGPT, Grok Bot and any MCP agent email you when something needs your attention. Private, free, one-click deploy to Cloudflare Workers.
Install / Use
claude mcp add CyrisXD -- npx -y github:CyrisXD/agent-notifyIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
CommunicationSupported Platforms
Tags
Our assessment of agent-notify
agent-notify scores 81/100 on our quality scale, 395th of 434 Communication skills we index.
Its MCP Server is 9.6 KB long, well organised into 11 sections with 4 code examples: a thorough specification that gives an agent plenty to work with.
It has 3 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated 2 days ago, so agent-notify is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 92/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.
AI review by kimi-k2.7-code on 2026-10-08. Automated pattern scan on 2026-10-08. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
agent-notify compared with similar skills
All 4 of these similar skills score higher than agent-notify; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| agent-notify (this skill)by CyrisXD | 81 | 3 | 2d ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 93.2k | today | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.6k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.3k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 86.2k | today | MCP Server |
Frequently asked questions
- How do I install agent-notify?
- Run
claude mcp add CyrisXD -- npx -y github:CyrisXD/agent-notify. The install tabs above show the steps for each supported agent. - Which AI agents does agent-notify work with?
- It is written for Claude Code, Claude Desktop and OpenAI Codex, as a MCP Server file. Other agents that read the same format can often use it too.
- Is agent-notify safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It is MIT-licensed and scores 92/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is agent-notify still maintained?
- The repository was last updated 2 days ago, so agent-notify is actively maintained.
Skill content
View source on GitHubagent-notify - Free Email Alerts

Always-on agents like OpenAI Dots and Grok Bot keep working after you close the app. agent-notify lets them, and Claude Code, Cursor or any script, email you when something needs your attention: a new lead, this week's free games, a failed backup, a finished report.
It's one Cloudflare Worker on your own free account, deployed in one click. It can only send email, and only to you. It has no access to your inbox, and there's no shared service in the middle.
Works with Claude Code, Cursor, Grok Bot, ChatGPT and OpenAI Dots (wherever custom connectors are available), and anything that can use an MCP server or send a web request.
Using Grok Bot? Its Gmail connector can't just send: it asks for read, modify and send access to your whole mailbox. agent-notify lets your bots email you without ever seeing your inbox. Add the agent-notify bot → · Grok Bot guide

Setup
You need: a free Cloudflare account, a domain on Cloudflare, and any inbox (Gmail, Proton, work email…). Nothing to install.
1. Prepare Cloudflare (once, 2 minutes)
- Onboard your domain for sending: click Onboard Domain and pick your domain.
- Verify your inbox: go to Destination addresses, add the address where you want alerts, and click the link Cloudflare emails you.
Domain already has email? That's fine. Onboarding doesn't touch your MX records. If it offers a new DMARC record, keep your existing one if other tools send as your domain.
2. Deploy
Click Deploy to Cloudflare above and fill in:
- Worker name: add a random suffix, e.g.
agent-notify-7f3k9q2m8x4w, so your Worker's URL can't be guessed (see Security) TO_ADDRESS: the inbox you verifiedFROM_ADDRESS: any address on your onboarded domain, e.g.alerts@yourdomain.com
3. Check your email
You'll get a one-time setup link. Open it, press Reveal, and follow the steps. That page is shown once, so save your token.
<img src="docs/setup-page.png" alt="The setup page: save your token, connect your agent, install the skill, send a test" width="460">Use it
After installing the MCP and Skill, just ask your agent in plain words:
Check the free games on Epic every Friday and email me the good ones.
Watch my inbox for new leads and email me a one-line summary of each.
Grok Bot: add the secret MCP URL from your setup page as a custom connector at grok.com/connectors with no authentication, then add the ready-made agent-notify bot. More routines and setup in the Grok Bot guide.
ChatGPT and other apps that only accept a URL: add the secret MCP URL from your setup page as a custom connector with no authentication.
Or send from any script:
curl -X POST "$AGENT_NOTIFY_URL" \
-H "Authorization: Bearer $AGENT_NOTIFY_TOKEN" \
-H "Content-Type: application/json" \
-d '{"subject":"Backup finished","text":"All 3 databases backed up."}'
The skill
The connection lets your agent send email. The agent-notify skill teaches it to do that well.
- Knows when to email. It always sends when you ask, and otherwise only for things you'd want to know about now: what you asked it to watch for, failures, decisions waiting on you, finished long jobs. It skips routine progress and doesn't repeat itself.
- Writes emails that are easy to read. Alerts are short: a clear subject like
[FAILED] nightly backup, what happened and what to do next. Digests you ask for (this week's free games, new leads, a report) can be as long as they need, laid out item by item with links so they're easy to skim on a phone. - Stays safe. It never puts passwords, tokens or secrets in an email, and it stops (rather than retrying) when a send limit is reached.
Install it in Claude Code with one command (also shown on your setup page):
mkdir -p ~/.claude/skills/agent-notify && curl -fsSL https://raw.githubusercontent.com/CyrisXD/agent-notify/main/skills/agent-notify/SKILL.md -o ~/.claude/skills/agent-notify/SKILL.md
Then just mention email ("email me when it's done") or call it directly:
/agent-notify find this week's free games and email me the best three
The skill is a plain Markdown file, so other agents that support skills or custom instructions can use it too.
Cost
Free. On Cloudflare's free plan it can't cost anything: going over a limit just pauses sending until the next day.
On the $5 Workers Paid plan, emails to your verified inbox are still free, and DAILY_LIMIT (default 100 a day) is set to stay within the included quota. Keep it at 100 unless you're happy to pay for extra emails. HOURLY_LIMIT (default 20) also stops any one agent from flooding you. If you're on Paid, set a budget alert anyway.
Security
agent-notify is secure by design: it can only ever email you. Nothing a caller sends can change the recipient, so even a misbehaving agent can't use it to leak your data to someone else or spam other people.
- Only you receive the emails: the recipient is fixed when you deploy, so callers can't choose who gets them.
- Your token is shown once and never emailed. Only its hash is stored.
- Your Worker's URL is hard to guess. Every request counts toward your Cloudflare usage, even rejected ones, and the default name
agent-notifyis the same for everyone, so a random name keeps junk traffic away.npm run deploypicks one for you on the first deploy (agent-notify-plus 24 random characters). With the Deploy button, type a suffix into the Worker name field yourself. This is only an extra layer: nothing works without your token, whatever the URL. - Setup happens once. Links only go to your inbox, expire in an hour, and stop working the moment your token is revealed. You also get an email when that happens, so you'd know if anyone else got there first. Only someone with access to your Cloudflare account can reset it (see below).
- A leaked token can only email you, up to
HOURLY_LIMITan hour andDAILY_LIMITa day. But those emails come from your own domain, so treat an unexpected agent-notify email asking you to log in, pay or run something as phishing. - Lost or leaked token? In Cloudflare go to Storage & Databases → KV, open this Worker's namespace and delete the
token_sha256key. The old token stops working within about a minute and setup reopens: open your Worker's URL and request a new link.
Prompt injection
Agents read web pages, emails and documents, and some of that content is written to trick them ("ignore your instructions and…"). That's prompt injection. No tool can fully prevent it, because it happens inside the agent before a request ever reaches agent-notify.
What agent-notify does is limit the damage. A tricked agent can't email your files or secrets to an attacker, because the only inbox it can reach is yours. The remaining risk is a misleading email to you, such as a fake "log in here" link copied from a page the agent read. So:
- Use a capable, current model. Newer frontier models are much better at spotting and ignoring injected instructions.
- Treat links in agent emails like links in any other email. An agent-notify email asking you to log in, pay, or run a command is a red flag. Check where the link goes first.
- Give agents only the access they need. agent-notify is safe to hand any agent, but the other tools it has (your files, accounts, shell) are what an injection would really go after.
- "email sending not authorized": your
FROM_ADDRESSdomain isn't onboarded (step 1). Fix it, wait a few minutes, then open your Worker's URL and click Email me a setup link. No redeploy needed. - Need to change
TO_ADDRESS,FROM_ADDRESS,HOURLY_LIMITorDAILY_LIMIT? Editwrangler.jsoncin the copy of this repo that Cloudflare created on your GitHub. Committing redeploys it. Don't change them in the Cloudflare dashboard: the next deploy resets them. - No setup email: check spam, then request one from your Worker's URL.
- Claude Code says the tool isn't available: run
claude mcp list. Ifagent-notifyis missing, re-run the command from your setup page (it uses--scope user, so it works in every folder). - Build fails with "build token … deleted or rolled": Worker → Settings → Builds → API token → Create new token, then Retry build.
- 429 "Hourly/Daily email limit reached": the hourly limit resets at the top of the hour, the daily one at 00:00 UTC. To raise them, change
HOURLY_LIMITorDAILY_LIMIT(see above).
git clone https://github.com/CyrisXD/agent-notify && cd agent-notify && npm i
# set TO_ADDRESS and FROM_ADDRESS in wrangler.jsonc
npm run deploy # first run gives the Worker a random, unguessable name and saves it in wrangler.jsonc
</details>
MIT licensed.
If agent-notify saves you some time, you can buy me a coffee:
<a href="https://buymeacoffee.com/FiRmVXOZh"><img src="https://cdn.buymeacoffee.com/buttons/v2/default-yellow.png" alt="Buy Me A Coffee" height="48"></a>
Related Skills
Agent-Reach
93.2kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.6kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
CowAgent
47.3kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Scrapling
86.2k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
