Mmcp.market

Is Palmyr MCP server safe?

Yes, with the usual care.

B80/100grade B

Safe to use. Minor gaps such as a missing repository or slower maintenance.

What to know before installing
  • highWrite-action tools reachable without authentication

Public scan report

scanner v0.1.9 · 2026-09-26 · same rubric, same numbers if you re-run it

1 high
  • –Code scanremote-only server, no package to scann/a
  • Live reliabilityremote reachable in 1516ms20/20
  • Tool poisoning33 tool descriptions checked15/15
  • Auth qualityopen endpoint exposes 12 write-action tools with no auth3/15
  • Maintenancelast push 13 days ago15/15
  • Maintainer identitynamespace and repository owner differ; GitHub account older than a year; website matches verified namespace7/10

Findings (1)

  • highWrite-action tools reachable without authenticationauth.open-write
Overall 80/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Other servers that do what Palmyr does

  • MCP
    Email infrastructure for AI agents: send, read replies as threads, campaigns, per-key limits.
    B
  • Blackwall
    API-key pre-action risk gate: any irreversible agent action (money, SQL, delete, email).
    B
  • e2a — email for AI agents
    Authenticated email gateway for AI agents — per-agent inboxes, HITL approval, SPF/DKIM verified.
    A

Palmyr reviews, tools and install