agentmail
Enables agents to autonomously manage dedicated email inboxes, facilitating seamless communication and email management.
Install this skill
or
81/100
Security score
The agentmail skill was audited on May 23, 2026 and we found 7 security issues across 3 threat categories. Review the findings below before installing.
Categories Tested
Security Issues
medium line 113
Webhook reference - potential data exfiltration
SourceSKILL.md
| 113 | - Real-time inbound email (webhooks) requires a public server — use `list_threads` polling via cronjob instead for personal use |
medium line 38
Access to hidden dotfiles in home directory
SourceSKILL.md
| 38 | Add to `~/.hermes/config.yaml` (paste your actual key — MCP env vars are not expanded from .env): |
medium line 38
Access to .env file
SourceSKILL.md
| 38 | Add to `~/.hermes/config.yaml` (paste your actual key — MCP env vars are not expanded from .env): |
low line 16
External URL reference
SourceSKILL.md
| 16 | - **AgentMail API key** (required) — sign up at https://console.agentmail.to (free tier: 3 inboxes, 3,000 emails/month; paid plans from $20/mo) |
low line 34
External URL reference
SourceSKILL.md
| 34 | - Go to https://console.agentmail.to |
low line 124
External URL reference
SourceSKILL.md
| 124 | - AgentMail console: https://console.agentmail.to |
low line 126
External URL reference
SourceSKILL.md
| 126 | - Pricing: https://www.agentmail.to/pricing |
Scanned on May 23, 2026
View Security Dashboard