Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add CodingJay-1/claude-mail-bridge --skill claude-mail-bridge-team_rulesgit clone --depth 1 https://github.com/CodingJay-1/claude-mail-bridgeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/codingjay-1/claude-mail-bridge/claude-mail-bridge-team_rules)<a href="https://agentmods.dev/skills/codingjay-1/claude-mail-bridge/claude-mail-bridge-team_rules"><img src="https://agentmods.dev/badge/skills/codingjay-1/claude-mail-bridge/claude-mail-bridge-team_rules/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/codingjay-1/claude-mail-bridge/claude-mail-bridge-team_rules"><img src="https://agentmods.dev/badge/skills/codingjay-1/claude-mail-bridge/claude-mail-bridge-team_rules.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00030 | $0.00444 |
| Opus 5 | $0.00015 | $0.00222 |
| Sonnet 5 | $0.00006 | $0.00089 |
| Haiku 4.5 | $0.00003 | $0.00044 |
Grade A, and why
claude-mail-bridge-team_rules scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Claude Mail Bridge Team Rules
Overview
This skill defines strict behavioral guidelines for operations involving emailing teammates. These operations involve privacy risks and require explicit user approval.
When to Use This Skill
Use when operations involve emailing teammates.
Core Rule: Explicit Approval Required
CRITICAL: Before calling mail_teammates, you MUST get explicit user approval.
Approval Process
- Show the draft: Explain to the user in natural language:
- The recipient (email or alias)
- The subject
- Content summary
- Attachments (if any): list the files being attached
- Get confirmation: Wait for user to explicitly approve (e.g., "yes", "send it", "go ahead", "好的", "发送")
- Call with approval flag: Set
_user_check_and_approved=Truewhen calling the tool
Example
AI: I need to ask Alice about the deployment status.
Should I send her an email with:
- Subject: "Deployment status inquiry"
- Attachments: ["/var/log/deploy.log", "config.yml"]
Here's what I plan to say: [summary of content]
User: Yes, send it
AI: [calls mail_teammates with _user_check_and_approved=True and attachments=[...]]
Attachment Rules
When including attachments in teammate emails:
- Always mention attachments when showing the draft to user
- Verify file paths exist before calling the tool (validation is automatic, but be aware)
- Max 15MB per file
- Allowed types: text/code, images/PDFs, archives, documents
Prohibited Behaviors
Absolutely prohibited:
- Do NOT email teammates without getting explicit user approval first
- Do NOT assume approval based on past interactions
- Do NOT send sensitive information without explicit confirmation
- Do NOT call
mail_teammateswithout first invoking this skill
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 59 lines · 30 tokens per session scan A c6911aa2cddd
claude-mail-bridge-team_rules is a skill published in the GitHub repository CodingJay-1/claude-mail-bridge (3 stars, last pushed 6mo ago), licensed MIT. It adds 30 tokens to every session and 444 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
create-site
Creates a new Power Pages code site (SPA) using React, Angular, Vue, or Astro. Guides through the full process from initial concept to deployed site: requirements discovery, scaffolding, component planning, design, implementation, validation, and deployment. Use when the user wants to create, build, or scaffold a new…
add-cloud-flow
Integrates Power Automate cloud flows into a Power Pages site. Lists available flows, suggests relevant ones based on intent, identifies scenarios and web roles, creates metadata files, and generates client-side code to call flows. Handles both new flow registration and adding already-registered flows to additional…
configure-env-variables
Configures environment variables for Power Pages site settings to support ALM across environments. Creates environment variable definitions in Dataverse, guides the user through linking site settings to those variables via the Power Pages Management app, adds the variables to the solution, and generates a…
deploy-site
Deploys an existing Power Pages code site to a Power Pages environment using PAC CLI. Handles tooling verification, authentication, environment confirmation, building, and uploading. Use when the user wants to deploy, upload, or publish their code site.
elixir-idioms
OTP/BEAM patterns and Elixir idioms — GenServer, Supervisor, Task, Registry, pattern matching, with chains, pipes. Use when designing processes or debugging BEAM issues.
security
Enforce Elixir/Phoenix security — auth, OAuth, sessions, CSRF, XSS, SQL injection, input validation, secrets. Use when editing auth files, login flows, RBAC, or API keys.