
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
@p-l-ta/mail-mcp
Advanced tools
MCP server that gives Claude (and other MCP hosts) full access to Mail.app on macOS — search, read, send, reply, flag, move, and more — across every account configured in Mail.app (iCloud, Exchange, IMAP, etc.).
mail-mcp.mcpb from the latest release.mcpb file — Claude Desktop installs it automaticallynpx @p-l-ta/mail-mcp
Or install globally:
npm install -g @p-l-ta/mail-mcp
mail-mcp
Point your MCP host at the mail-mcp binary (stdio transport). Example config:
{
"mcpServers": {
"mail-app": {
"command": "npx",
"args": ["@p-l-ta/mail-mcp"]
}
}
}
Grant these to the application that runs the MCP host (Claude Desktop, Amazon Quick, etc.):
| Permission | Where to grant |
|---|---|
| Full Disk Access | System Settings → Privacy & Security → Full Disk Access |
| Automation → Mail | System Settings → Privacy & Security → Automation |
The MCP server process inherits permissions from the host application that launches it.
| Tool | Description |
|---|---|
search_emails | Search messages via the Envelope Index database with rich filters |
read_email | Read the full body of a message by its RFC message-id |
list_accounts_and_mailboxes | List all configured accounts and mailboxes with unread counts |
list_recent | List recent messages in a specific mailbox |
list_senders | Grouped summary of senders with message and unread counts |
send_email | Send a new email from one of the configured accounts |
reply_to_email | Reply to an existing message by RFC message-id |
set_message_flags | Set read and/or flagged status on a message |
move_email | Move a message to a different mailbox |
trash_email | Move a message to Deleted Messages |
create_mailbox | Create a new mailbox/folder in an account |
bulk_mark_read | Mark all messages in a mailbox and/or from a sender as read |
get_unsubscribe_link | Extract unsubscribe URLs from a message's headers and body |
empty_mailbox | Delete every message in a mailbox at once (Junk, Trash, etc.) |
npm install
npm run dev # tsx watch — live reload
npm test # vitest unit tests
npm run build # compile TypeScript → dist/
npm run mcpb # build Claude Desktop extension → build/mail-mcp.mcpb
Interactive MCP testing:
npm run build
npx @modelcontextprotocol/inspector node dist/server.js
mail-mcp is a local MCP server that runs entirely on your Mac. It has no backend, no telemetry, and makes no network requests of its own.
What it accesses:
~/Library/Mail/) — read-only, used for search queriesWhat it does NOT do:
All email data stays on your device and is only passed to the MCP host (Claude Desktop or another client) as part of normal tool responses. You control exactly which tools Claude can invoke.
MIT
FAQs
MCP server exposing Mail.app to Claude and other MCP hosts
We found that @p-l-ta/mail-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.