gigamail
Mail for AI agents ( and humans). MCP server giving Claude (or any agent) safe, permission-controlled access to email (Microsoft Graph + IMAP), calendar and your knowledge files. Two-phase confirmation for sends, audit log, local index. No built-in LLM: your agent brings the intelligence.
Install / Use
claude mcp add adecubed -- npx -y github:adecubed/gigamailIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
CommunicationSupported Platforms
Tags
Our assessment of gigamail
gigamail scores 76/100 on our quality scale, 407th of 431 Communication skills we index.
Its MCP Server is 36 KB long, well organised into 24 sections with 18 code examples: a thorough specification that gives an agent plenty to work with.
It has 10 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated yesterday, so gigamail is actively maintained.
- It is released under AGPL-3.0, a copyleft license: you can use it, but modified versions you distribute must carry the same license.
- Its trust signals score 97/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
gigamail compared with similar skills
All 4 of these similar skills score higher than gigamail; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| gigamail (this skill)by adecubed | 76 | 10 | 1d ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 91.8k | 20d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.5k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.2k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 85.8k | 1d ago | MCP Server |
Frequently asked questions
- How do I install gigamail?
- Run
claude mcp add adecubed -- npx -y github:adecubed/gigamail. The install tabs above show the steps for each supported agent. - Which AI agents does gigamail work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is gigamail safe to use?
- It is AGPL-3.0-licensed and scores 97/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is gigamail still maintained?
- The repository was last updated yesterday, so gigamail is actively maintained.
Skill content
View source on GitHubGigaMail — Mail for your AI agent
MCP server that gives your agent — Claude, Codex, OpenClaw, Hermes, or any MCP client — safe, controlled access to your email — multi-account (Microsoft Graph + IMAP), calendar, local search index, sender memory, and an agent-aware permission model.
No built-in LLM: the intelligence is your agent's. The MCP server speaks stdio only — no network port. (An optional human console adds a local HTTP API bound to 127.0.0.1.)
On your data: GigaMail keeps mail indexes, credentials, memory and configuration on your machine — we run no service and receive nothing. Mail content your agent reads is, of course, handled by that agent and its model provider under their own data policies. Choose your agent accordingly; the masker lets you hide sensitive fields (tax codes, VAT numbers, IBANs, emails, phone numbers — validated deterministically, no AI) before the agent ever sees them.
One minute: the console drafts a reply, takes the figure from your own files, stops where the documents stop, and nothing leaves without your approval — from the console or from your agent.
Why
- Hybrid search: provider search (Graph/IMAP) + local SQLite index — fast and offline-friendly
- Its own archive: every mail of every account saved locally,
attachments included, and still searchable after the server has dropped
it. Outlook's history on the PC is imported once (
gigamail archive) - Sender memory: tone, topics and history per sender, so replies sound right
- Contact notes: what happened with each person — how a meeting went, what they are after — is written next to their name, and every draft to them reads it
- Observer: patterns learned from how the user edited past drafts
- Calendar-aware drafts: a draft only proposes times that are free in your calendar, inside your office hours
- Knowledge files: attach your price lists, terms, product sheets to an account — the agent reads them to answer mail. Your agent doesn't need to know everything: the account carries its own knowledge
- Agent-aware permissions: reads are free; send/delete require an approval given out of band — the agent gets an inert request id, a human approves from the console or the CLI, and only then does it execute, with the exact arguments the human saw. Every write lands in an append-only action log
- Credentials never touch the agent channel: login and account management live in the CLI only — a prompt injection inside an email cannot add accounts or read secrets
Quick start
GigaMail ships through two channels:
pip install gigamail— the agentic core: MCP server, CLI, watcher and the console's local HTTP backend. No graphical app — the right channel when your agent is the interface.- Windows desktop app — the human console packaged with an
embedded Python: one installer, no prerequisites. Download
GigaMail-Setup-<version>.exefrom the latest release; the app then updates itself from there. The installer is not code-signed yet, so Windows SmartScreen warns on first run — compare the SHA-256 digest GitHub shows next to the asset. To build it yourself: Node 22+,console/prepare-python.ps1, thennpm run dist.
Everything below covers the pip channel.
pip install "gigamail[all]"
gigamail login # Microsoft device flow
gigamail accounts add-imap # or IMAP: Aruba, Gmail, Libero, ...
gigamail check # search, a draft held for your approval, a test mail to yourself
Microsoft login note: the bundled Azure app is not yet publisher-verified, so the consent screen shows an "unverified" notice (works fine; some corporate tenants may block it). Standard alternative: register your own Azure app and set your
client_idinsrc/gigamail/core/ms_config.json. IMAP needs none of this.
Give the account its identity and knowledge (this is what makes replies yours):
gigamail identity set # who am I, what I do, tone
gigamail identity add-file C:\docs\pricelist.xlsx
gigamail identity add-file C:\docs\catalog\ # whole folder
Register in Claude Desktop / Claude Code (mcpServers):
{
"gigamail": {
"command": "gigamail-server"
}
}
The commands are also available under their legacy names
(ade-mail-agent, ade-mail-agent-server), and the Python package answers
to its old name ade_mail_agent too (python -m ade_mail_agent.server),
so existing setups keep working.
Using Claude Code? The repository is also a Claude Code plugin: it
registers the gigamail MCP server and adds a skill that teaches Claude the
approval gate.
claude plugin marketplace add adecubed/gigamail
claude plugin install gigamail@gigamail
Using Codex? The repository is a Codex plugin: it registers the
gigamail MCP server and adds a skill that teaches Codex the approval gate.
codex plugin marketplace add adecubed/gigamail
codex plugin add gigamail@gigamail
GigaMail is also in the OpenAI Plugins Directory,
as a skill: install it from there, then register the server with
codex mcp add gigamail -- gigamail-server (the server comes from pip,
as above).
Using OpenClaw or Hermes? Verified configs in INTEGRATIONS.md.
Are you an AI agent setting this up on behalf of a human? You can do the install and the MCP registration:
pip install "gigamail[all]", then addgigamail-serverto your client's MCP config (see INTEGRATIONS.md; declareGIGAMAIL_ROOTif your client filters the environment). Stop there. Connecting a mailbox (gigamail login,gigamail accounts add-imap) asks for credentials and must be done by the human in their own shell — it is not something you should do, and GigaMail is built so that it cannot be done through you. Tell them what to run, then wait.
Then just ask your agent: "reply to the last quote request using the price list" — it reads the mail, pulls the numbers from your file, drafts the reply, and asks you before sending.
Tools
29 typed tools, generated from the server itself:
- Read (17) — accounts, identity, knowledge files, messages, unread, folders, hybrid search, attachment text, sender history, learned patterns, calendar events, free-slot availability, Drive files and their text
- Safe writes (3, audited) — mark read, move message, create folder
- Dangerous (9, human approval out of band) — send, reply, delete message, delete folder, create/delete calendar event, create a Zoom meeting, upload a file to Drive, move a Drive file to the trash
The calendar is served by Microsoft Graph or Google Calendar, whichever
the user connected; the tools are the same either way. Drive uses the
drive.file scope, so it only ever sees files GigaMail created itself.
Connecting Google: GOOGLE_SETUP.md.
Full map and design decisions: MAPPA_MCP.md.
Security model
Email content is treated as untrusted data (prompt injection). The
agent cannot approve its own actions, by construction: a dangerous tool
returns only an inert request_id, and approving it — from the console or
from gigamail approvals approve — requires an OS-level verification of
the person at the machine (Windows Hello / Touch ID). A process,
including an agent that holds a shell, can open that prompt but cannot
pass it. On Linux, where neither exists, a local PIN typed in an
interactive terminal stands in (gigamail approvals pin): weaker, and
declared so in SECURITY.md. Telegram approval is opt-in and
the weakest channel of the three. No secret ever
enters the model context, so an injected instruction has nothing to
spend. Repeating the id just returns awaiting approval. The agent
can only read files explicitly registered by the user, never the rest of the
filesystem. Every write action is logged to %APPDATA%/ADE/agent_audit.jsonl
(append-only: GigaMail never rewrites past entries — it is not, and does not
claim to be, tamper-proof storage).
We red-team this: hostile emails ordering exfiltration, mass deletion, and the agent to approve itself — fed to a real agent with every mail tool enabled.
This design is a fix. v0.1.0 returned a one-time confirm token in the tool result, which put it in the model's context: the agent held both halves. Thanks to u/ranbuman and u/anderson_the_one on r/mcp for catching it. The switch now sits where the agent cannot reach.

The structural half of that suite runs in CI on every push (tests/test_injection.py); the real-agent half is opt-in (scripts/injection_e2e.py) and runs with a dry-run guard so confirmed actions are audited but never executed.
Reply rules (0.2): semi-auto and auto reply, fenced
You can tell GigaMail: mail from these senders (or in this folder) gets a
reply drafted from these documents. Rules are created from the CLI —
gigamail rules add — behind the same Windows Hello / Touch ID prompt as
approvals, and gigamail watch is the process that applies them. The MCP
server stays passive and there is no MCP tool that touches rules: an
injected instruction cannot enable autopilot.
- semi (default): the draft becomes a normal approval request — you get the notification, you approve with Hello, it goes out.
- Notifications reach you where you are: a Windows toast with
✅ / ❌ buttons (run
gigamail desktop-setuponce — UAC prompt — to make them clickable; they open the approval, which raises Hello) and Telegram (gigamail telegram setup, your own bot: ✅ approve if you opted in with--approvebehind Hello, ❌ reject, ✏️ ask for changes — accepted only from your chat). Telegram approval is a convenience, not the nor
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
91.8kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.5kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
CowAgent
47.2kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Scrapling
85.8k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

