MailFathom is listed as active in the registry but did not answer our last check. Last commit 22 Sep 2026.
Security-first, self-hosted email archive with search, cited answers, and sending for AI agents.
We read the source, 8 h ago · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
using var browser = Process.Start(new ProcessStartInfo(address.AbsoluteUri) { UseShellExecute = true });
[GeneratedRegex(@"(?:https?://)?hooks.slack.com/(?:services|workflows|triggers)/[A-Za-z0-9+/]{43,56}", SecretRegexEngine.MatchOptions, SecretRegexEngine.MatchTimeoutMilliseconds)]
Found in continuous integration, deployment or infrastructure files, or in a neighbouring package of the same monorepo. None of this is installed when you add the server: it describes how the project is built and released. We list it because a leaked key in a build pipeline is still a real problem, but it is not something this server does on your machine.
- name: Create or update the release from the changelog
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
COPY frontend/package.json frontend/pnpm-lock.yaml frontend/pnpm-workspace.yaml frontend/.npmrc frontend/
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 13 min ago.
claude mcp add mailfathom --transport http https://{mailfathom_host}/mcp
{
"mcpServers": {
"mailfathom": {
"url": "https://{mailfathom_host}/mcp"
}
}
}
[mcp_servers.mailfathom]
url = "https://{mailfathom_host}/mcp"
{
"mcpServers": {
"mailfathom": {
"url": "https://{mailfathom_host}/mcp"
}
}
}
{
"mcpServers": {
"mailfathom": {
"url": "https://{mailfathom_host}/mcp"
}
}
}
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://{mailfathom_host}/mcp | streamable-http | answering | 0 ms | 13 min ago |
Thin MCP and CLI proxy for AI agent and MCP security auditing via a hosted backend
Pre-install security scans for npm packages, MCP servers, and AI agents with cited verdict evidence.
Agentic SDLC governance and security controls for AI coding agents working with GitHub.
Process management and monitoring for AI agents with strict security boundaries
Security scanner for AI Agent skills, plugins, and MCP servers with A-F grading.
Website intelligence for AI agents: tech stack, hosting, security posture, SEO, and DNS.
Thrd MCP: agent email tools for events/threads, safe send/reply, usage, trust and security.
Enterprise code intelligence for M&A, security audits, and tech debt. Hosted server with 200k free.
Answers built from our own checks of this server.