Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add plugins/tokencanopy/e2a/marketplace/plugin marketplace add tokencanopy/e2agit clone --depth 1 https://github.com/tokencanopy/e2aGrade A, and why
e2a scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "e2a",
"owner": {
"name": "TokenCanopy",
"email": "[email protected]",
"url": "https://e2a.dev"
},
"metadata": {
"description": "e2a plugins for Claude Code — open-source email API for applications and AI agents",
"version": "0.9.5"
},
"plugins": [
{
"name": "e2a",
"description": "Open-source email API for applications and AI agents — transactional sending from any product, per-agent two-way inboxes, HITL approval, structured SPF/DKIM/DMARC evidence, and a queryable event log. 78 MCP tools over hosted streamable HTTP with OAuth.",
"category": "productivity",
"source": "./plugins/e2a",
"homepage": "https://e2a.dev"
},
{
"name": "e2a-labs",
"description": "Experimental Agentify, Autopilot, and Tether workflows for e2a. Requires the core e2a plugin for MCP tools and authentication.",
"category": "productivity",
"source": "./plugins/e2a-labs",
"homepage": "https://e2a.dev"
}
]
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 29 lines scan A c3c06db2142a
e2a is a plugin published in the GitHub repository tokencanopy/e2a (184 stars, last pushed yesterday), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
shipmail
Operate secure custom-domain business email, calendars, and agent inboxes with Shipmail.
apple-mail-mcp
Plugin marketplace listing 1 plugin: apple-mail.
apple-mail
Natural language interface for Apple Mail — search, compose, triage, organize, and analyze email with 24 MCP tools and an expert email management skill.
better-email-mcp
Email management via IMAP/SMTP — multi-account.
mail-muncher
mail-muncher — an email client for AI agents: filtered, read-only mail from any IMAP server or Gmail, delivered to disk and served over MCP.
readndraft
Plugin marketplace listing 1 plugin: readndraft.