SkillAgentSearch skills...

imap-mcp

MCP server for IMAP mailboxes: read, search, organise and draft mail — it deliberately cannot send

Install / Use

claude mcp add ni-c -- npx -y github:ni-c/imap-mcp

If the server publishes to npm under a different name, use that package instead — check the repo README.

About this skill
🔌

MCP Server

Model Context Protocol server

Quality Score

80/100

Supported Platforms

Claude Code
Claude Desktop

Our assessment of imap-mcp

imap-mcp scores 80/100 on our quality scale, 406th of 434 Communication skills we index.

Its MCP Server is 23 KB long, well organised into 20 sections with 8 code examples: a thorough specification that gives an agent plenty to work with.

It has 3 GitHub stars, so there is little community track record yet; judge it on its content.

Substance
30/30
Structure
20/20
Description
12/15
Adoption
3/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated today, so imap-mcp is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 87/100, with 2 cautions from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.

AI review by kimi-k2.7-code on 2026-10-08. Automated pattern scan on 2026-10-08. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

imap-mcp compared with similar skills

All 4 of these similar skills score higher than imap-mcp; compare them before choosing.

SkillScoreStarsUpdatedFormat
imap-mcp (this skill)by ni-c803todayMCP Server
Agent-Reachby Panniantong10093.2ktodayCLAUDE.md
headroomby headroomlabs-ai10074.6ktodayCLAUDE.md
CowAgentby zhayujie10047.3ktodayCLAUDE.md
Scraplingby D4Vinci10086.2ktodayMCP Server

Frequently asked questions

How do I install imap-mcp?
Run claude mcp add ni-c -- npx -y github:ni-c/imap-mcp. The install tabs above show the steps for each supported agent.
Which AI agents does imap-mcp work with?
It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
Is imap-mcp safe to use?
Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It is MIT-licensed and scores 87/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is imap-mcp still maintained?
The repository was last updated today, so imap-mcp is actively maintained.

imap-mcp

<!-- badges: start -->

CI OpenSSF Scorecard Socket Badge Glama score <br> npm version container image HTTP via mcp-hub <br> docs sponsor

<!-- badges: end -->

A Model Context Protocol (MCP) server for any IMAP mailbox. It speaks IMAP rather than one vendor's API, so it works with whatever provider you already have.

Lets MCP clients like Claude Code, Claude Desktop or Codex read and search your mail, organise it into folders, save attachments and draft replies — with every message fenced as untrusted content, and the write tools off unless you turn them on.

Eleven tools, not fifty: a mail account is a workflow, not an API surface, so related operations are folded into one tool with a mode rather than split across many. And eleven is the ceiling, not the floor — IMAP_ALLOW_TOOLS=essential registers a curated six instead, and under the read-only default that narrows to four. See choosing which tools load.

<!-- <picture> is resolved against the colour scheme of the page showing it, so GitHub picks the variant that matches its own theme toggle. npm strips <picture> and <source> when it sanitises the README and keeps the <img>, which is why that fallback carries its own dark card. The URLs are absolute because relative ones are simply invisible on the npm package page. --> <picture> <source media="(prefers-color-scheme: dark)" srcset="https://imap-mcp.ni-c.de/architecture-dark.svg"> <source media="(prefers-color-scheme: light)" srcset="https://imap-mcp.ni-c.de/architecture-light.svg"> <img src="https://imap-mcp.ni-c.de/architecture.svg" alt="An MCP client talking to imap-mcp over stdio, which connects to an IMAP server over TLS and returns message bodies fenced as untrusted content" width="800"> </picture> <img src="https://imap-mcp.ni-c.de/demo.gif" alt="Listing the tools registered under the read-only default, listing an inbox, and reading a phishing message — which comes back with the injection shapes named first, the body fenced line by line, and the tracking beacon defused" width="800">

What makes it different

It cannot send mail. That is the feature. An agent with access to private data, exposure to untrusted content, and a channel to the outside world is exploitable by anyone who can put a message in the inbox — the pattern that produced EchoLeak, where one crafted email exfiltrated internal data from Microsoft 365 Copilot with no user interaction. This server has the first two and deliberately not the third. save_draft writes the reply into your Drafts folder; you send it from your own mail client. No amount of clever text in a message can make this server post anything anywhere.

Writes are off until you turn them on. With only IMAP_HOST, IMAP_USER and IMAP_PASSWORD set, the server registers six read tools and nothing else. The mailbox tools appear with IMAP_READ_ONLY=false — note the default is true, the opposite of the other servers in this family, because this one reaches a mailbox. Tools that are off are not registered at all — a capability the model cannot see is one it cannot be talked into using.

Mail is treated as hostile input, because it is. Anyone in the world can put text in your inbox. Message bodies are fenced between markers carrying a per-call random nonce, and every line inside them is prefixed with that nonce, so the "this is data" signal does not stop at the edges of a long forwarded thread. A reminder follows the block, because otherwise the last instruction-shaped sentence in the model's context is the attacker's. Zero-width characters and directional overrides are stripped before the model sees anything, hidden HTML elements are dropped on a best-effort basis (the fencing, not the stripping, is what carries the weight), and markdown image syntax — inline and reference style — is defused so a rendering client cannot be made to fetch a tracking URL.

That covers folder names too: a folder name is chosen by whoever created the folder, which on a shared mailbox is not necessarily you. list_mailboxes returns the name twice — path exactly as the server spelled it, because that is the handle every other tool takes, and display_name cleaned up for reading, with a warning on the entry when the two differ.

Alongside the message you get a server-side assessment: the SPF/DKIM/DMARC verdicts with the authserv-id they came from, which prompt-injection shapes matched, and which words mix Latin with Cyrillic or Greek letters. When something matches, the warning is the first thing in the result rather than a field buried in JSON.

Those verdicts carry a forgeable flag, and by default it is always true. A sender can write an Authentication-Results header of their own, and if your provider does not add one, theirs is the only one there — nothing inside the message distinguishes the two. Set IMAP_TRUSTED_AUTHSERV_ID to the id your provider stamps (it is the first token of the header on any message you already have) and only that id counts as authentic. Until you do, spf=pass is reported as what it is: a claim, from a header anyone could have written.

"New mail" that actually works. The server tags messages it has handed over with a custom IMAP keyword (AiSeen by default), so list_new_messages returns each message once. The human \Seen state is never touched — everything is read with BODY.PEEK.

Deleting and moving ask a person. Where the client supports MCP elicitation, delete_messages, move_messages and deleting a folder raise a real dialog that the model cannot answer on its behalf. Where it does not, they fall back to a two-call token — and say so, rather than implying somebody approved. ELICITATION=false takes that fallback deliberately; it never removes the guard. See Asking a person.

Requirements

  • Node.js 22 or newer
  • An IMAP account. Providers with two-factor authentication generally need an app-specific password.

Configuration

| Variable | Required | Default | Description | | --------------------------- | -------- | ------------- | ------------------------------------------------------------ | | IMAP_HOST | yes | — | Hostname of the IMAP server, e.g. imap.example.net | | IMAP_USER | yes | — | Account username, usually the address | | IMAP_PASSWORD | yes | — | Password or app-specific password | | IMAP_PORT | no | 993 / 143 | Defaults by TLS mode | | IMAP_TLS | no | implicit | implicit, starttls or none | | IMAP_MAILBOX | no | INBOX | Mailbox the message tools default to | | IMAP_READ_ONLY | no | true | Exactly false registers the five mailbox tools | | IMAP_ALLOW_TOOLS | no | — | Tool names, list_* prefixes or essential | | IMAP_DENY_TOOLS | no | — | Same syntax; subtracted from the allow list | | IMAP_SEEN_KEYWORD | no | AiSeen | Keyword for new-mail tracking; empty turns it off | | IMAP_TRUSTED_AUTHSERV_ID | no | — | The authserv-id your provider stamps; see below | | IMAP_DRAFTS_MAILBOX | no | auto | Overrides the folder found via the \Drafts flag | | IMAP_MAX_MESSAGES | no | 100 | Default page size | | IMAP_MAX_ATTACHMENT_BYTES | no | 1048576 | Ceiling for returning an attachment inline | | IMAP_MAX_DOWNLOAD_BYTES | no | 26214400 | Ceiling for writing one to disk | | IMAP_MAX_EXTRACT_BYTES | no | 10485760 | Ceiling for reading a document's text; max 67108864 | | IMAP_ATTACHMENT_TYPES | no | see below | Comma-separated content-type allowlist | | IMAP_DOWNLOAD_DIR | no | — | Setting it allows saving attachments there | | IMAP_INSECURE_TLS | no | false | Exactly true accepts a self-signed certificate | | ELICITATION | no | true | false replaces the dialog with the token. Not prefixed |

Booleans are compared against the literal string true; 1, yes and True are not true. IMAP_READ_ONLY is the mirror image: only the literal false turns it off, so a typo leaves the write tools unregistered.

Choosing which tools load

IMAP_ALLOW_TOOLS and IMAP_DENY_TOOLS take comma-separated tool names; a trailing * matches a whole family. essential is a curated preset of six — list_mailboxes, list_new_messages, list_messages, get_message, set_message_flags and move_messages. Four of those are read tools, so it stays useful under the read-only default.

IMAP_ALLOW_TOOLS=essential
IMAP_ALLOW_TOOLS=list_new_messages,get_message,move_messages
IMAP_DENY_TOOLS=delete_messages

One boundary the list cannot draw: move_messages copies as well as moves (mode: "copy"), and the two are one tool. Denying move_messages removes both; there is no way to keep moving and forbid copying, or the other way round. Both modes ask for confirmation.

An entry that matches no tool aborts startup and names it, so a typo cannot silently hide a tool — an absent tool is not something anyone traces back to an environment variable. A filtered tool is never registered, so it is absent from tools/list and unknown to tools/call alike, exactly like a write tool under IMAP_READ_ONLY.

It covers tools. The attachment resources this server also exposes are not filtered.

If you run several of these servers at once, mcp-hub is the other answer — its /hub endpoint replaces every server's tools with six meta-tools. The password is deleted from the process environment as soon as it is read, so it is not visible to child processes or in /proc/<pid>/environ.

Without IMAP_DOWNLOAD_DIR this server never writes to the filesystem. The three size limits are separate on purpose, because they answer three different questions: IMAP_MAX_ATTACHMENT_BYTES protects the model's context window, IMAP_MAX_DOWNLOAD_BYTES protects your disk,

Truncated for display — read the full file on GitHub.

Related Skills

View on GitHub
GitHub Stars3
CategoryCommunication
Updated13h ago
Forks5

Languages

TypeScript

Trust signals

87/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

2 low
imap-mcp — MCP Server: Install & Safety Check | SkillAgent