B-

mailbox.bot

https://mailbox.bot/api/mcp
81/100 · MCP Trust Grade · checked 6h ago · MCP 2025-11-25
Watched since 2026-06-03 — behavioral baseline locked. We re-check this server's tool surface on a schedule; if it adds, removes, or silently rewrites a tool (rug-pull), we record it.

What it offers — 29 tools · Developer Tools

get_mailbox

Get your agent's managed receiving endpoint when the account has access to managed receiving. For generally available inbound context, use list_inboun

list_packages

List inbound packages for approved managed receiving/package accounts with optional filters by status, carrier, and date. Returns tracking number, car

get_package

Get full package details including photos, tracking events, shipping label data (carrier, addresses, weight), forwarding status, storage location, and

get_package_photos

Get photos for a package with OCR-extracted text and confidence scores. Filter by photo type to get only exterior shots, label closeups, barcode scans

request_action

Request a physical action on a package at the facility. Actions include forwarding to another address, shredding, scanning documents, holding for pick

request_scan

Request document scanning (OCR + structured data extraction) for a package. The facility will scan the document and extract text, addresses, dates, an

get_scan_results

Get document scan results including raw OCR text, structured data fields (addresses, dates, amounts), and confidence scores. Returns empty if scan is

add_tag

Add a tag/label to a package for categorization and filtering. Tags are free-form strings. Adding the same tag twice is a no-op.

add_note

Add an observation or context note to a package. Notes are visible to the facility operator and the renter. Use for recording decisions, observations,

create_rule

Create a standing instruction that auto-triggers actions when incoming packages match conditions. Rules run on every new package and execute the speci

register_expected

Pre-register an expected inbound shipment so it is auto-matched when it arrives at the facility. Optionally specify an action to auto-execute on arriv

get_usage

Get usage summary and billing events for a time period. Returns itemized events (scans, forwards, mail sends) with costs, plus period totals. Defaults

list_inbound_forwarding_addresses

List the renter’s private inbound forwarding aliases on forward.mailbox.bot. These are the unique intake email addresses an operator, assistant, provi

list_inbound_mail

List forwarded inbound mail items captured from private forwarding aliases. Default output includes compact draft_context so an LLM or external agent

get_inbound_mail

Get one forwarded inbound mail item with compact draft_context by default. Use this before drafting an outbound reply when you need sender context, re

list_postal_threads

List physical-mail threads that group inbound mail context, human review, and outbound sends. Use this to understand which inbound items and outbound

get_postal_thread

Get one physical-mail thread with optional timeline events. Use this to explain how a generated outbound mail piece relates back to prior inbound scan

update_action

Push notes, structured data, or a clarification response to an existing action request. Use this to add agent reasoning, attach extracted data, or res

+11 more tools

Spec conformance20%60
Security (OWASP MCP)30%100
Reliability / performance20%70
Tool hygiene15%74
Transparency / provenance15%90

Observed behavior

No proxied traffic observed for this host yet. Connect it at /connect and its grade gains a measured Reliability score + per-tool behavioral evidence — the half a static scan can't produce.

Findings

No blocking issues found in the static + spec checks.
Grade another server

We re-grade mailbox.bot on a schedule and alert your Slack/webhook the moment its tools change or its grade drops — rug-pull insurance for the connection.

Share this report card

A 1200×630 card with the grade + audit — drop it in a post, Slack, or your repo.

MCP Trust report card — mailbox.bot grade B-
Share on X Open card image

Embed this grade

A live badge — it re-verifies itself and shows current stability. Static scorecards can't. Paste it in your README or site to show users you're independently audited.

MCP Trust Grade B- · wmcp.sh
[![MCP Trust Grade B-](https://wmcp.sh/mcp/grade/mailbox.bot/badge.svg)](https://wmcp.sh/mcp/grade/mailbox.bot)
<a href="https://wmcp.sh/mcp/grade/mailbox.bot"><img src="https://wmcp.sh/mcp/grade/mailbox.bot/badge.svg" alt="MCP Trust Grade B- · wmcp.sh"></a>

Agents: check this before connecting

Add the wmcp.sh trust oracle as an MCP server and call grade_mcp_server / check_mcp_drift in your agent's pre-connection gate:

https://wmcp.sh/mcp/trust
How this grade is computed. An open, independent rubric — Spec conformance (20%), Security mapped to the OWASP MCP Top 10 (30%), Reliability (20%), Tool hygiene (15%), Transparency (15%) — run by connecting to the server and inspecting its real MCP surface. The grade is free and identical whether or not the operator pays. v1 uses static + spec signals from a single connection; continuous uptime, real latency, and annotation-truthing (declared readOnly vs observed behavior) layer on via the wmcp.sh proxy.