{"name":"io.github.RolloutsAI/mails-agent-email","slug":"rolloutsai-mails-agent-email","title":"Mails.ai — Agent Email","description":"A real inbox for AI agents: send, receive and thread email, behind a prompt-injection firewall.","url":"https://mcp.market/server/rolloutsai-mails-agent-email","rating":null,"grade":"C","score":55,"certified":false,"status":"active","category":"email","tags":["email","ai"],"presence":{"score":12,"stars":null,"forks":null,"downloads_week":50,"last_push_at":null,"license":"MIT"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":null,"website":"https://mails.ai","version":"0.2.9","remotes":[],"packages":[{"registryType":"npm","registryBaseUrl":"https://registry.npmjs.org","identifier":"@mailsai/mcp-server","version":"0.2.9","transport":{"type":"stdio"},"environmentVariables":[{"description":"Your mails.ai API key. Use an mk_test_ key to run against the sandbox or an mk_live_ key to send real mail. Free key at https://mails.ai","isRequired":true,"isSecret":true,"name":"MAILS_API_KEY"},{"description":"Override the API base URL. Defaults to the hosted mails.ai API; only needed for staging or self-hosted deployments.","name":"MAILS_BASE_URL"}]}],"tools":[{"name":"mails.allowlist_address","description":"Override suppression for one address with a >=20 char attestation.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mails.check_suppression","description":"Check if an address is suppressed.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mails.create_agent","description":"Create a new agent.","write_action":true,"price_micros":0,"input_schema":null},{"name":"mails.create_draft","description":"Stage a draft. Optionally pass send_at to schedule.","write_action":true,"price_micros":0,"input_schema":null},{"name":"mails.forward","description":"Forward a message to new recipients.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mails.get_event","description":"Get a specific inbound event by ID.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mails.get_received","description":"Get one received message including extracted reply text.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mails.get_reputation","description":"Get an agent's sending-reputation health (0-1) + its 30-day bounce/complaint/reply counts. The firewall auto-suspends an agent that crosses a 0.3% complaint rate — well before the upstream provider's 0.5% line — so check this to catch an at-risk agent before it gets paused.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mails.get_thread","description":"Get a full thread with all messages in chronological order.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mails.get_usage","description":"Get the current billing period usage.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mails.list_agents","description":"List the agents in the workspace. Returns SENDABLE agents by default (status=live); archived agents cannot send, so they are excluded unless you ask for them. Pass status=\"all\" to see archived ones too.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mails.list_messages","description":"List recent cold/first-contact inbound (message.received) for an agent — senders that are NOT replying to one of your sends.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mails.list_received","description":"List recently received messages.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mails.list_replies","description":"List recent reply events (reply.received) for an agent.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mails.list_threads","description":"List threads (conversations) for the workspace or a specific agent.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mails.me","description":"Who am I — returns the authenticated workspace, agent, tier, and API-key scopes. Call this first to confirm the connection is live.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mails.reply","description":"Reply to a previously-received message. Sets In-Reply-To + Re: subject server-side.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mails.send","description":"Send an email. `agent` is OPTIONAL: omit it and the workspace's single agent is used, or one is created for you (named from `from`) — so a first send needs no setup. Pass `agent` only when the workspace has several and you must say which. The reputation firewall runs on every send: an agent auto-suspended for crossing a 0.3% complaint rate is blocked (422 agent_paused), suppressed recipients are s","write_action":true,"price_micros":0,"input_schema":null},{"name":"mails.send_draft","description":"Send a previously-created draft.","write_action":true,"price_micros":0,"input_schema":null},{"name":"mails.test_inbound","description":"SANDBOX (test key only): simulate an email arriving to one of your agents, so you can exercise the whole two-way loop — receive → prompt-injection scan → reply — with NO live mail server and no waiting. This runs the REAL reputation firewall. Read the VERDICT from top-level `quarantined` (boolean — true means we judged it an attack); the evidence sits in the `classification` block: injection_score","write_action":false,"price_micros":0,"input_schema":null}],"scan":{"score":55,"grade":"C","scanned_at":"2026-09-20T16:16:33.233Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-20T16:16:33.189Z","components":{"code":{"score":25,"max":25,"notes":["5 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":6,"max":15,"notes":["static API keys via environment variables"]},"maintenance":{"score":3,"max":15,"notes":["no repository listed"]},"identity":{"score":2,"max":10,"notes":["no repository or website to verify"]}},"findings":[{"id":"maint.no-repo","severity":"low","component":"maintenance","title":"No source repository listed"}],"inputs":{"packages":[{"registryType":"npm","identifier":"@mailsai/mcp-server","version":"0.2.9","found":true,"license":"MIT","hasInstallScripts":false,"dependencyCount":2,"publishedAt":"2026-09-04T08:08:59.698Z","weeklyDownloads":50}],"repo":{"found":false},"icon":{"url":"https://mails.ai/apple-touch-icon.png?v=2","source":"site","width":180,"height":180},"presence":{"stars":null,"forks":null,"downloadsWeek":50,"license":"MIT","lastPushAt":null,"score":12}}}},"grade_history":[],"reviews":[]}