Claude security directory

AgentMail

Published by AgentMail, Inc.

High risk

AgentMail gives AI agents their own email inboxes. Through this connector, an agent (or you, in Claude) can spin up a dedicated inbox on the fly, then send, receive, reply to, and forward email, with full thread context, drafts, and attachments, entirely through tool calls. Unlike traditional email APIs built for one-way notifications, AgentMail is built for two-way conversations: an agent can read an incoming thread, understand it, and respond in context, just like a person would. This makes email a first-class communication and identity channel for agents, letting them sign up for services, coordinate with people, and talk to other agents. Key capabilities exposed over MCP: • Inboxes: create, list, get, update, and delete agent inboxes • Messages: send, reply, forward, list, and update • Threads: list, read, label, and delete full conversation threads • Search: full-text search across threads and messages • Drafts: create, list, read, update, send (with scheduling), and delete • Attachments: retrieve attachments by ID, with text extraction for PDF/DOCX Connect in seconds via OAuth using your AgentMail console identity. No API key required in Claude. Sign up free at console.agentmail.to.

Security assessment

Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: The connector can read email content including full threads, drafts, and attachments, which may contain sensitive personal, business, or credential-reset information.
  • Can change or update your information: It can update inbox settings and modify messages/threads/drafts (e.g., labels or metadata), which may affect organization, workflow, or recordkeeping.
  • Can permanently delete data: It can delete drafts, inboxes, and entire conversation threads, potentially causing irreversible loss of communications and evidence trails.
  • Can send messages as you: It can send, reply, and forward emails from an agent inbox, enabling impersonation/phishing or accidental disclosure if misused.
  • Sends your data to outside companies: Forwarding messages and sending emails transmits content to external recipients and mail infrastructure outside your organization’s control.
  • Stores long-lived access tokens: OAuth-based access may rely on stored/refreshable tokens; compromise of tokens could allow ongoing access to inbox contents and sending capabilities.

Available capabilities

This add-on exposes 24 tools or capabilities.

  • auth_me
  • create_draft
  • create_inbox
  • delete_draft
  • delete_inbox
  • delete_thread
  • forward_message
  • get_attachment
  • get_draft
  • get_inbox
  • get_thread
  • list_drafts
  • list_inboxes
  • list_messages
  • list_threads
  • reply_to_message
  • search_messages
  • search_threads
  • send_draft
  • send_message
  • update_draft
  • update_inbox
  • update_message
  • update_thread

The interactive security report will load automatically.