
mailwarden
A reliable, **native** Gmail MCP server for inbox triage — full mailbox control, with **no send tools by design**. Runs locally against the **live** Gmail API: no mailbox mirror, no cache, no cloud copy of your mail. Every call goes straight to Google, and the only local state is your own OAuth token in `~/.mailwarden/`. ### What it does - **Mailbox-side snooze** — archive a thread now, have it resurface in the inbox on a date or time. Built on dated labels plus a sweep, so it works from any client, is visible in Gmail itself, and survives restarts. - **Search you can trust** — Gmail's own index silently drops `is:unread` in some operator combinations; every hit is re-verified against its live labels before a tool sees it. - **Triage digest and signals** — sender / label / age buckets, plus per-thread flags (newsletter, automated, calendar, reply-to mismatch) read from headers and MIME structure, never guessed from wording. - **Bulk operations with a dry run** — `bulk_modify`, `bulk_unsubscribe` and `sweep_snoozed` rehearse the identical path and stop before the first write or outbound request. - **Unsubscribe** — per-sender overview and RFC 8058 one-click opt-out. The URL comes from the message's own `List-Unsubscribe` header and is never a tool parameter. - **Least privilege** — tool tiers (`read` / `manage` / `filters`) decide both the registered tools and the OAuth scopes requested. A `read` deployment can change nothing and makes no outbound request at all. ### Deliberately missing There is no compose, reply, forward or send tool, and `create_filter` never produces a forwarding rule — so a prompt-injected mail has no exfiltration path. Nothing is deleted permanently either: trash and untrash only. ### Setup One-time consent to **your own** Google Cloud OAuth client; the refresh token stays on your machine: ``` npx -y mailwarden --auth # one-time consent npx -y mailwarden --check # diagnose the setup ``` Full guide: https://github.com/csitte/mailwarden/blob/main/docs/SETUP.md — threat model: https://github.com/csitte/mailwarden/blob/main/SECURITY.md
First seen 2 Oct 2026. Evidence as of 5 Oct 2026.
Tools
No tool list captured yet.
Change history
No changes since the first observation. The first snapshot is the baseline.
| Source | Listing | First seen | Last seen | Versions |
|---|---|---|---|---|
| Smithery | csitte/mailwarden | 2 Oct 2026 | 5 Oct 2026 | 1 |