
Research
GemStuffer Campaign Abuses RubyGems as Exfiltration Channel Targeting UK Local Government
GemStuffer abuses RubyGems as an exfiltration channel, packaging scraped UK council portal data into junk gems published from new accounts.
gsd-agent-inbox
Advanced tools
Give any AI agent a disposable email inbox in one tool call. MCP server for email verification, auth flows, and testing.
Give any AI agent a disposable email inbox in one tool call.
npx gsd-agent-inbox
The interactive installer auto-detects your AI coding agents (Claude Code, Codex CLI, Cursor, Gemini CLI, Windsurf), configures the MCP server, and installs the optional skill for each.
When launched by an MCP client (non-TTY), it starts the MCP server normally. When you run it from a terminal, you get the installer.
An MCP server that creates real, temporary email addresses on demand. Your agent can sign up for services, receive confirmation emails, extract verification links, and clean up — without you lifting a finger.
No API keys. No accounts. No configuration. Works with any email-sending service — Supabase, Resend, SendGrid, Postmark, AWS SES, whatever.
AI agents hit a wall when a service requires email verification. They can fill out a sign-up form, but they can't receive the confirmation email. So they stop and ask you to do it.
Agent: create_inbox({ prefix: "signup", name: "test" })
→ signup-1712345678@somedomain.com (name: test)
Agent: [fills sign-up form with that email]
Agent: verify_email({ address: "test", subject_contains: "confirm" })
→ Email verified successfully!
Verification URL: https://myapp.supabase.co/auth/v1/verify?token=abc123
HTTP Status: 200
Agent: delete_inbox({ address: "test" })
→ Done.
If you prefer to configure manually instead of using the installer:
claude mcp add agent-inbox -- npx -y gsd-agent-inbox
Or add to ~/.claude/settings.json:
{
"mcpServers": {
"agent-inbox": {
"command": "npx",
"args": ["-y", "gsd-agent-inbox"]
}
}
}
Add to ~/.cursor/mcp.json:
{
"mcpServers": {
"agent-inbox": {
"command": "npx",
"args": ["-y", "gsd-agent-inbox"]
}
}
}
Add to ~/.codeium/windsurf/mcp_config.json:
{
"mcpServers": {
"agent-inbox": {
"command": "npx",
"args": ["-y", "gsd-agent-inbox"]
}
}
}
Any client that supports stdio transport:
{
"command": "npx",
"args": ["-y", "gsd-agent-inbox"]
}
git clone https://github.com/gsd-build/agent-inbox.git
cd agent-inbox
npm install
npm run build
npm start
| Tool | What it does |
|---|---|
create_inbox | Spin up a temporary email address. Optional prefix for readability, optional name for easy reference. |
check_inbox | Check for messages. Returns subjects, bodies, and auto-extracted verification links. |
wait_for_email | Poll until a matching email arrives. Filters by sender and subject. Auto-retries with backoff. |
verify_email | One-shot verification: polls for confirmation email, extracts the link, visits it via HTTP. Three steps in one tool call. |
list_inboxes | Show all active inboxes with names and providers. |
delete_inbox | Destroy an inbox and its backing account. |
Give inboxes a name for easy reference across multiple tool calls:
create_inbox({ prefix: "signup", name: "main" })
wait_for_email({ address: "main", subject_contains: "confirm" })
delete_inbox({ address: "main" })
The installer can optionally add a skill file that teaches your AI agent when and how to use agent-inbox — so it reaches for the inbox tools automatically when it encounters auth flows, email verification, or sign-up testing.
To install the skill manually:
mkdir -p ~/.claude/skills/agent-inbox
curl -fsSL https://raw.githubusercontent.com/gsd-build/agent-inbox/main/skill/SKILL.md \
-o ~/.claude/skills/agent-inbox/SKILL.md
Uses mail.tm as the primary provider with automatic fallback to 1secmail if mail.tm is down. No API keys or accounts required.
wait_for_email retries with backoff (3s → 5s → 10s → 15s)MIT
FAQs
Give any AI agent a disposable email inbox in one tool call. MCP server for email verification, auth flows, and testing.
The npm package gsd-agent-inbox receives a total of 24 weekly downloads. As such, gsd-agent-inbox popularity was classified as not popular.
We found that gsd-agent-inbox demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
GemStuffer abuses RubyGems as an exfiltration channel, packaging scraped UK council portal data into junk gems published from new accounts.

Company News
Socket was named to the Rising in Cyber 2026 list, recognizing 30 private cybersecurity startups selected by CISOs and security executives.

Research
Socket detected 84 compromised TanStack npm package artifacts modified with suspected CI credential-stealing malware.