Email skills for agents

Three open-source Agent Skills that teach your coding agent to send, receive and safely act on email with mails.ai.

Setup

Add them in seconds

One command adds the skills to your project. It finds all three and asks which to add; --skill picks one, -a the agent and -g installs them for your user.

npx skills add mailsai/skills

In action

See the skills in action

Claude Code, with the skills added, checks a message before it answers it.

What’s inside

Three skills, two tools

Each skill is a folder: a SKILL.md, reference notes and runnable examples.

  • mails

    What an agent needs to use its own address: sending, receiving, threads, drafts and webhooks, by API, SDK or MCP.

  • agent-inbox

    For an agent that acts on the mail it reads: five levels of protection, and webhook signature checks.

  • email-best-practices

    Custom sending domains, bounces, complaints and unsubscribes, and what mails.ai refuses and the law requires.

  • CLI

    The mails command line: send and receive email, follow events live, and add the MCP server to your AI client.

  • MCP server

    The hosted server gives any MCP client the email tools. The skills package registers it as an Agent Plugin.

Frequently asked questions

What are Agent Skills?
Folders of instructions an agent loads when a task needs them, in the open Agent Skills format: a SKILL.md, reference notes the agent reads when it needs them, and runnable TypeScript and Python examples.
Which agents can use them?
Any agent that reads Agent Skills. The skills command installs them into Claude Code, Codex, Cursor, GitHub Copilot, Gemini CLI, Windsurf, Cline, Continue and many more. For any other agent, copy the folders to where it reads skills.
How do I install only one skill?
Add --skill and its name: npx skills add mailsai/skills --skill mails. Add -a claude-code to pick the agent, and -g to install for your user instead of the current project.
Can I install them without the skills command?
Yes. Copy the three folders by hand. For Claude Code, put them in ~/.claude/skills to use them in every project, or in .claude/skills inside one project.
Do I still need the MCP server?
The skills teach your agent to use mails.ai through the API, the SDKs or MCP, so pick whichever your agent has. The package is also an Agent Plugin that registers the hosted MCP server, so a client that installs the plugin gets both.
Does the plugin hold my API key?
No. Its mcp.json holds only the server’s address. Your client opens mails.ai’s sign-in in the browser, where you choose the workspace and press Allow. On a server or in CI, add the server with an API key instead.
Can I try the examples without sending real mail?
Yes. Use a test key (mk_test_…): nothing is delivered and nothing is billed. The examples need Node.js 18 or newer, or Python 3.10 or newer.
What does agent-inbox protect against?
Mail written to steer your agent. It is for an agent that reads incoming email and then replies, calls tools or changes anything because of it, with five levels of protection and the steps to check webhook signatures.
Are the skills open source?
Yes. They are MIT licensed and made by the mails.ai team.

“Replies come back as events with an injection score already on them. We deleted a whole layer of parsing code the week we switched, and we gate on the quarantine flag, so our agent never sees the ones that look like attacks.”

Tomás VargaStaff Engineer, Cinderjay

“Moving our agent onto our own domain was a few DNS records at the registrar. No nameserver move, and our existing mail kept working. Replies to the agent still come back to its inbox, threaded with the message they answer.”

Ishani VaidyaCTO, Sedgequay

“The 422 on cold outreach is the feature I didn’t know I wanted. An agent can’t talk itself into emailing strangers.”

Marcus FeldFounder, Marrowkite

“Our tests send to the test address and wait for the real reply, so the whole loop is covered before a customer ever writes in. It answers in about a second, which keeps the suite fast.”

Ana Lucía RíosEngineering Lead, Gorsefinch

“Adding the MCP server was one JSON block. Claude Code could send and read its own inbox a minute later.”

Jonah AbramsDeveloper, Wickerjay

“A reputation score per agent tells us exactly which one needs attention, instead of one number for the whole account. It comes from each agent’s own replies, bounces and complaints, and we read it from the API.”

Mei Lin ZhouOperations, Larchwhistle

“Sends and replies have separate allowances, so a busy inbox never eats our sending quota. Pricing was the easy part.”

Kwabena AdomakoFounder, Oxbowlark

“Half our agents are LangGraph in Python and half are Node. Both SDKs make the same calls, so the team doesn’t have to think about it.”

Sofia BrandtEngineer, Moss & Ladder

“Signed webhooks, retries with backoff and an event id to dedupe on. The boring plumbing, done properly.”

Nikhil BhonsleBackend Lead, Thimblecrow

“We signed up, made a key and sent our first message without talking to anyone, and the free tier never asked for a card. That’s how infrastructure should feel.”

Frieda WesselFounder, Ploverwick Studio

Give your first agent an inbox

Free covers 3,000 emails and 3,000 inbound replies a month, with no card. Upgrade when your agents get busy.

Get your API key