{"generated_at":"2026-08-17T10:36:11+00:00","item":{"added_at":"2026-07-05","analysis_method":"capability_triage","category":"Web Connector","description":"AgentMail gives AI agents their own email inboxes. Through this connector, an agent (or you, in Claude) can spin up a dedicated inbox on the fly, then send, receive, reply to, and forward email, with ","did":"ant-dir-agentmail","homepage_url":"https://www.agentmail.to/","icon":"https://agentmail.to/favicon.ico","id":"ant.dir.agentmail","installs":12339,"last_scanned":"2026-07-05","license":"","long_description":"AgentMail gives AI agents their own email inboxes. Through this connector, an agent (or you, in Claude) can spin up a dedicated inbox on the fly, then send, receive, reply to, and forward email, with full thread context, drafts, and attachments, entirely through tool calls.\n\nUnlike traditional email APIs built for one-way notifications, AgentMail is built for two-way conversations: an agent can read an incoming thread, understand it, and respond in context, just like a person would. This makes email a first-class communication and identity channel for agents, letting them sign up for services, coordinate with people, and talk to other agents.\n\nKey capabilities exposed over MCP:\n• Inboxes: create, list, get, update, and delete agent inboxes\n• Messages: send, reply, forward, list, and update\n• Threads: list, read, label, and delete full conversation threads\n• Search: full-text search across threads and messages\n• Drafts: create, list, read, update, send (with scheduling), and delete\n• Attachments: retrieve attachments by ID, with text extraction for PDF/DOCX\n\nConnect in seconds via OAuth using your AgentMail console identity. No API key required in Claude. Sign up free at console.agentmail.to.","name":"AgentMail","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=ant-dir-agentmail&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"AgentMail, Inc.","publisher_url":"https://www.agentmail.to/","repository_url":"","risk":"high","risk_severity":"high","security_risks":[{"description":"The connector can read email content including full threads, drafts, and attachments, which may contain sensitive personal, business, or credential-reset information.","risk_type":"reads_private_data","severity":"medium","title":"Reads your private information"},{"description":"It can update inbox settings and modify messages/threads/drafts (e.g., labels or metadata), which may affect organization, workflow, or recordkeeping.","risk_type":"modifies_data","severity":"medium","title":"Can change or update your information"},{"description":"It can delete drafts, inboxes, and entire conversation threads, potentially causing irreversible loss of communications and evidence trails.","risk_type":"deletes_data","severity":"high","title":"Can permanently delete data"},{"description":"It can send, reply, and forward emails from an agent inbox, enabling impersonation/phishing or accidental disclosure if misused.","risk_type":"sends_messages_as_you","severity":"medium","title":"Can send messages as you"},{"description":"Forwarding messages and sending emails transmits content to external recipients and mail infrastructure outside your organization’s control.","risk_type":"forwards_data_to_third_party","severity":"low","title":"Sends your data to outside companies"},{"description":"OAuth-based access may rely on stored/refreshable tokens; compromise of tokens could allow ongoing access to inbox contents and sending capabilities.","risk_type":"requires_persistent_credentials","severity":"medium","title":"Stores long-lived access tokens"}],"signature_status":"unknown","source_code_reviewed":false,"tags":["deletes_data","forwards_data_to_third_party","modifies_data","reads_private_data","requires_persistent_credentials","sends_messages_as_you"],"tools":[{"description":"Returns information about the currently authenticated AgentMail identity/session.","name":"auth_me"},{"description":"Creates a new email draft in an agent inbox for later sending.","name":"create_draft","risk":{"category":"state_change","level":"medium","why":"Creates new email content that could contain sensitive data and be sent later."}},{"description":"Creates a new dedicated agent email inbox.","name":"create_inbox","risk":{"category":"state_change","level":"medium","why":"Provisions a new communication identity/channel that could be used for outreach, sign-ups, or impersonation-like activity."}},{"description":"Deletes an existing email draft.","name":"delete_draft","risk":{"category":"destructive","level":"high","why":"Draft deletion can permanently remove content needed for auditability or later recovery."}},{"description":"Deletes an agent inbox and its associated data.","name":"delete_inbox","risk":{"category":"destructive","level":"high","why":"Inbox deletion can permanently remove email history, identity, and associated messages/threads."}},{"description":"Deletes an entire email conversation thread.","name":"delete_thread","risk":{"category":"destructive","level":"high","why":"Thread deletion can permanently remove records of communications and attachments."}},{"description":"Forwards an email message to one or more recipients.","name":"forward_message","risk":{"category":"sends_externally","level":"medium","why":"Forwarding can exfiltrate sensitive email content and attachments to external parties."}},{"description":"Retrieves an email attachment by ID (including extracted text for supported formats).","name":"get_attachment"},{"description":"Fetches a specific email draft by ID.","name":"get_draft"},{"description":"Fetches details for a specific agent inbox.","name":"get_inbox"},{"description":"Retrieves a full email conversation thread and its messages.","name":"get_thread"},{"description":"Lists email drafts in an inbox.","name":"list_drafts"},{"description":"Lists available agent inboxes for the authenticated identity.","name":"list_inboxes"},{"description":"Lists email messages within an inbox or thread.","name":"list_messages"},{"description":"Lists conversation threads in an inbox.","name":"list_threads"},{"description":"Replies to an existing email message within a thread.","name":"reply_to_message","risk":{"category":"sends_externally","level":"medium","why":"Replies transmit content to recipients and can unintentionally disclose sensitive information."}},{"description":"Performs full-text search across email messages.","name":"search_messages"},{"description":"Performs full-text search across email threads.","name":"search_threads"},{"description":"Sends an existing draft email (optionally scheduled).","name":"send_draft","risk":{"category":"sends_externally","level":"medium","why":"Sending a draft transmits content externally and could be used for spam/phishing or accidental disclosure."}},{"description":"Composes and sends a new email message.","name":"send_message","risk":{"category":"sends_externally","level":"medium","why":"Sending email can leak sensitive data and can be abused to contact third parties as the user/agent."}},{"description":"Edits an existing email draft's content or metadata.","name":"update_draft","risk":{"category":"state_change","level":"medium","why":"Alters draft contents, potentially changing intent/recipients and introducing sensitive information."}},{"description":"Updates settings or metadata for an agent inbox.","name":"update_inbox","risk":{"category":"state_change","level":"medium","why":"Inbox configuration changes can affect routing/identity and how messages are handled."}},{"description":"Updates email message metadata (e.g., status/labels) in an inbox.","name":"update_message","risk":{"category":"state_change","level":"medium","why":"Changing message state/labels can hide, misroute, or disrupt triage and compliance workflows."}},{"description":"Updates thread metadata such as labels or other organizational attributes.","name":"update_thread","risk":{"category":"state_change","level":"medium","why":"Thread metadata changes can alter visibility/organization and impact auditing or discovery."}}],"tools_count":24,"type":"web_connector","url":"https://claude.ai/directory/a99a3b09-26fc-4251-a412-fa2593123267","uuid":"a99a3b09-26fc-4251-a412-fa2593123267","version":""},"query_key":"agentmail inc agentmail","schema_version":1,"status":"match"}
