Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ’¬ Communication
  3. Pylos MCP
Pylos MCP logo
Health: ActiveRecent health check succeeded.Last checked 9/23/2026, 1:01:46 AM

Pylos MCP

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View Repository1 GitHub StarsTotal stargazers on GitHub for the source repository (1 stars).Visit Website

Read-focused, prompt-injection-hardened email MCP server for any IMAP provider

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β€” we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "pylos-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "pylos-mcp"
      ]
    }
  }
}

πŸ’‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Directory Badge Claim listing AlternativesπŸ’¬ More in Communication

Documentation Overview

pylos-mcp logo, an envelope with a keyhole in its flap

pylos-mcp

Read-focused, prompt-injection-hardened email MCP server for any IMAP provider.

Anyone in the world can put text in your inbox, and the moment an AI assistant reads that inbox, anyone in the world can put text in front of your assistant. pylos-mcp is an email MCP server built around that fact. It lets Claude, or any MCP client, search, read and draft your mail while treating every message as what it really is, input from a stranger. Mailbox content is fenced as data before the model sees it, and there is no bcc field for an injected email to quietly copy someone with.

It runs on your machine and speaks plain IMAP, so it works with Gmail, iCloud, Yahoo, GMX, Fastmail, mailbox.org, Posteo, Proton via Bridge, or anything self-hosted, and your credentials never leave home. Out of the box it can read and draft. Anything riskier, moving, sending, deleting, is a separate switch that stays off until you flip it.

What this can never do

Mail is attacker-controlled text, so the hard limits live in the architecture rather than in a prompt. No message can talk the server out of any of these.

  • No raw HTML ever reaches the model. Bodies come from the plain-text part when one exists or are converted to text otherwise. Invisible characters that hide instructions from a human reader while staying readable to a model are stripped.
  • Untrusted content is fenced. Everything from the mailbox, bodies, subjects, sender names, folder listings, Sieve script text, is wrapped in a labeled delimiter before the model sees it, and the delimiter is neutralized inside the content, so a message cannot forge its way out of the fence. The few lines outside it are server-authored and never carry message content.
  • No bcc field exists anywhere, on drafts or sent mail. A bcc recipient receives a full copy of a message while appearing nowhere in it, exactly the invisibility an injected email wants. The field is absent rather than guarded, so there is nothing to talk the model into.
  • Deleting a message moves it to Trash. There is no expunge and no permanent-delete option, and the tool result never claims a permanence this server does not offer.
  • Sieve access is read-only, permanently. Server-side filter rules can forward, auto-reply and notify, each an exfiltration channel that survives revoking the app password or uninstalling this server. Write access is left out entirely, not defended.

Sending is the other risky door, so it starts closed even with the send capability on. Until SEND_ALLOWLIST says who may be addressed, every send is refused, and the refusal names the two ways to open the gate. SEND_ALLOWLIST=* allows anyone, visibly and on purpose.

Fencing reduces prompt-injection risk, nothing eliminates it. The model still reads text written by strangers, so treat every response that includes message content as untrusted input, not ground truth. The finer design notes live in SECURITY.md.

Quick start

Add the server to your MCP client's config. For Claude Desktop that file is claude_desktop_config.json.

config.json
{
  "mcpServers": {
    "pylos-mcp": {
      "command": "npx",
      "args": ["-y", "pylos-mcp"],
      "env": {
        "PROVIDER": "mailbox.org",
        "EMAIL_USER": "you@example.com",
        "EMAIL_PASSWORD": "your-app-password"
      }
    }
  }
}

Use an app password, not your account's regular login password. The next section says which providers insist on one. Restart the client and the read and draft tools appear. Later config changes need the same treatment, a newly enabled capability only registers its tools after a full client restart, and in Claude Desktop toggling the server off and on is not always enough.

Provider setup

Set PROVIDER to one of gmail, icloud, yahoo, gmx, fastmail, mailbox.org or posteo and the matching IMAP, SMTP and Sieve hosts and ports fill themselves in.

Gmail, iCloud, Yahoo and Fastmail refuse regular account passwords over IMAP, so an app password is the only way in. Google only offers one once 2-Step Verification is on, and iCloud wants two-factor authentication on the Apple ID first. mailbox.org, GMX and Posteo accept the account password, though an app password is still the wiser choice.

Proton Mail goes through Bridge. Leave PROVIDER unset and set IMAP_HOST and IMAP_PORT to what Bridge shows. The username is the address Bridge tells you to use, and the password is the one in Bridge's Mailbox details, IMAP section, not your Proton account password. Bridge defaults to STARTTLS while this server only speaks implicit TLS, so switch Bridge to SSL in its Advanced Settings. Bridge's certificate is self-signed, so export it and point TLS_CA_FILE at it.

Self-hosted servers also leave PROVIDER unset. Set IMAP_HOST, plus SMTP_HOST or SIEVE_HOST when those optional tiers are enabled, and authenticate however your server requires. For a private CA, point TLS_CA_FILE at the CA certificate. Verification itself always stays on, this only adds a trust anchor.

Capabilities

Capabilities are independent switches, not a ladder. Reading is always on, drafting starts on, everything else stays off until you list it in CAPABILITIES. A switched-off tier has its tools left out of the tool list entirely, not merely refused, so a model never learns a disabled tool exists.

TierDefaultTools
readalways onsearch_emails, get_email, get_attachment, list_folders
draftsoncreate_draft
manageoffmove_email, set_flags
sendoffsend_email
deleteoffdelete_email
sieve-readofflist_sieve_scripts, get_sieve_script

Enable more with a comma-separated list, for example CAPABILITIES=drafts,manage,delete.

Suspicion warnings

The server also tells you what is suspicious about a message. Four detectors annotate get_email results with a line above the content, written entirely in the server's own words and never quoting the content that tripped them.

Code
Warnings: hidden_text (412 hidden characters via display:none), encoded_blob (base64 run of 600 characters)
  • Hidden text. Text concealed with the common CSS tricks, display:none, invisible or one-pixel fonts, matching text and background colors, off-screen positioning, aria-hidden. It covers inline styles and attributes, a tripwire, not a rendering engine. Newsletters legitimately hide short preview text, so the warning fires only past a threshold, unless the hidden text itself contains an instruction-like phrase or an encoded run, which warns at any length. The text stays in the body by default. STRIP_HIDDEN_TEXT=true drops it instead, with a note of how much was dropped.
  • Instruction patterns. A deliberately small set of phrases that address an AI as an instruction target, like "ignore previous instructions". Small so that an inbox merely talking about AI stays quiet. Extend it with FLAG_EXTRA_PATTERNS, pipe-separated phrases matched as case-insensitive literals.
  • Encoded blobs. Long contiguous base64 or hex runs in the body, reported with their length and never decoded.
  • Sender mismatch. A Reply-To address on a different domain than the From address, or a From display name carrying an address on a domain the real sender does not use. Subdomains count as the same domain, so a provider replying from one of its own stays quiet. The Reply-To address itself is shown inside the fenced content, so the model can see where a reply would actually go.

Warnings annotate, they never withhold. The message always comes back, and each detector has its own toggle in the reference below.

Configuration reference

All configuration is environment variables, validated at startup. Invalid configuration fails immediately with an actionable message, never partway through a conversation. An empty value counts as unset, since bundle managers fill optional fields users leave blank with empty strings.

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Communication View all alternatives
  • Lumail logoLumail

    Official Lumail email marketing MCP for campaigns, subscribers, and workflows.

    πŸ’¬ Communication1 views
    Compare vs Lumail β†’
  • Slack MCP Server logoSlack MCP Server

    The most powerful MCP server for Slack Workspaces.

    πŸ’¬ Communication1 views
    Compare vs Slack MCP Server β†’
  • Telnyx logoTelnyx

    Official TypeScript library for the Telnyx API

    πŸ’¬ Communication1 views
    Compare vs Telnyx β†’
  • Line Bot MCP Server logoLine Bot MCP Server
    Verified

    MCP Server for Integrating LINE Official Account

    πŸ’¬ Communication8 views
    Compare vs Line Bot MCP Server β†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks β€” not a rating.

GitHub stars
1
Stargazers on the source repository.
npm downloads
504
Package downloads in the last 30 days.
Last commit
23d ago
Most recent push to the default branch.

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about Pylos MCP

Add the following block to your claude_desktop_config.json under mcpServers: "mcpServers": { "pylos-mcp": { "command": "npx", "args": ["-y","pylos-mcp"] } }

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewPylos MCP AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/pylos-mcp?style=directory)](https://allmcps.com/mcp/pylos-mcp)
HTML Embed
<a href="https://allmcps.com/mcp/pylos-mcp"><img src="https://allmcps.com/api/badge/pylos-mcp?style=directory" alt="Pylos MCP on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ’¬Communication
More technical detailsExpand β–Ύ
TransportSTDIO
RuntimeNode.js
Last updatedSep 1, 2026
3/7 checks healthy over the last 45d
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars1
GitHub Star CountTotal stargazers on GitHub representing community popularity (1 stars).
Last commit23d ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Sep 1, 2026
npm downloads504/mo
Monthly npm DownloadsAverage monthly package installs recorded from npm registry statistics.
43Quality signal: Fair Β· 43/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools15/30
Adoption & activity7/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

Supply-chain signal

No high-severity advisories surfaced by our automated scan.

Critical 0High 0Medium 0Low 0

Scanned 6d ago via OSV.dev Β· pylos-mcp (npm)

β˜… FeaturedAllMCPs Server logo

AllMCPs Server

The official MCP server for AllMCPs.com - submit and manage tools directly from your AI. The open directory for MCP servers. Connect Claude, Cursor, Windsurf, and AI agents to databases, tools, files, and APIs. Explore 10,000+ servers. AllMCPs is the premier, open directory for discovering, evaluating, and installing Model Context Protocol (MCP) servers to equip AI agents and LLMs with real-world superpowers.

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ’¬ Communication β†’Best MCP servers for Slack & Communication β†’Alternatives to Pylos MCP β†’Install in Claude DesktopInstall in CursorInstall in VS CodeSetup guides for all 13 MCP clients