Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add mupengi-bot/mupengism --skill mailgit clone --depth 1 https://github.com/mupengi-bot/mupengismWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/mupengi-bot/mupengism/mail)<a href="https://agentmods.dev/skills/mupengi-bot/mupengism/mail"><img src="https://agentmods.dev/badge/skills/mupengi-bot/mupengism/mail/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/mupengi-bot/mupengism/mail"><img src="https://agentmods.dev/badge/skills/mupengi-bot/mupengism/mail.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00014 | $0.00587 |
| Opus 5 | $0.00007 | $0.00293 |
| Sonnet 5 | $0.00003 | $0.00117 |
| Haiku 4.5 | $0.00001 | $0.00059 |
Grade A, and why
Mail scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 67 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Platform Detection & Routing
macOS: Use Apple Mail SQLite queries (100x faster than AppleScript).
Cross-platform: Use himalaya CLI for full IMAP/SMTP operations.
Never mix approaches in same task. Commit to one to avoid state conflicts.
Apple Mail SQLite Gotchas
Query path: ~/Library/Mail/V*/MailData/Envelope\ Index
Key tables: messages (subject, sender, date_received), addresses, mailboxes.
Force sync first: osascript -e 'tell app "Mail" to check for new mail'. SQLite reads stale data otherwise.
Recent mail filter: WHERE date_received > strftime('%s','now','-7 days')
Join pattern: messages→addresses on message_id for sender lookup.
Attachments: Check messages.attachment_count > 0, files in ~/Library/Mail/V*/MAILBOX/Messages/.
himalaya CLI Patterns
Install: cargo install himalaya or brew install himalaya.
Always use: --output json flag for programmatic parsing.
List emails: himalaya envelope list -o json (NOT message list).
Folder operations: himalaya message move <id> <folder> - folder names are case-sensitive.
Cache refresh: Run himalaya folder list after server-side folder changes.
Send Protocol
Draft-review-send workflow: Compose → show user full content → send after explicit OK.
Reply threading: Include In-Reply-To and References headers or thread breaks.
himalaya send: himalaya message send reads RFC 2822 from stdin.
SMTP rejection: Some servers reject if From header doesn't match authenticated user.
Credential Management
macOS Keychain: security add-internet-password -s imap.gmail.com -a [email protected] -w 'app-password'
Gmail/Google Workspace: Requires App Password with 2FA enabled, NOT regular password.
OAuth tokens: himalaya supports XOAUTH2 via token_cmd in config.toml.
Thread Intelligence
Thread by In-Reply-To chain, not subject matching. "Re:" prefix is unreliable.
Polling intervals: 15-30 min max. Use himalaya envelope watch for real-time when available.
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 67 lines · 14 tokens per session scan A 350e6da0de76
Mail is a skill published in the GitHub repository mupengi-bot/mupengism (10 stars, last pushed 2mo ago), licensed MIT. It adds 14 tokens to every session and 587 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
cron-management
Skill for reading and writing cron.md in the correct format for scheduled LLM or command tasks. Use when: editing cron.md, adding or changing cron schedules, or removing periodic jobs.
zoom-meeting-scribe
A listen-only note-taking workflow for Zoom meetings. It receives live transcript sections, organizes what was said, and prepares a report after the meeting ends.
notion-tool
Notion integration tool for searching, reading, creating, and updating pages and databases via the API. Use when: editing Notion pages, adding database rows, or searching a workspace.
chatwork-tool
Chatwork integration tool for send/receive messages, search, unreplied checks, and room listing. Use when: posting to Chatwork, listing rooms, checking unreplied threads, searching messages, or handling mentions.
discord-tool
Discord integration tool for messaging, search, guild and channel listing, and reactions. Use when: posting to Discord, listing channels, searching messages, or adding reactions in guilds.
google-calendar-tool
Google Calendar integration tool for listing and creating events via OAuth2 Calendar API access. Use when: checking upcoming events, creating appointments, or updating your schedule.