Agent skill

Mailbox Operations Hub

by agentscope-ai in agentscope-ai/QwenPaw

Connects, registers, and operates a personal mailbox, reading, searching, sending, and organizing, through a managed mail server for nine domains.

Apache-2.0Auto-check passedProductivity & Automation

Install Mailbox Operations Hub

skills CLI
$ npx skills add agentscope-ai/QwenPaw --skill mailbox -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install agentscope-ai/QwenPaw mailbox --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/agentscope-ai/QwenPaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/qwenpaw/agents/skills/mailbox-en .claude/skills/mailbox && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mailbox
GitHub stars
35k
Token cost
~2.6k tokens
SKILL.md length
1,218 words
Files
1
Skills in repo
20
Repo updated
First seen
Licence
Apache-2.0

At a glance

Connects, registers, and operates a personal mailbox, reading, searching, sending, and organizing, through a managed mail server for nine domains.

  • Works in 2 steps: Read public mailbox state → After successful registration
  • Connecting a personal mailbox for the first time
  • SKILL.md covers Supported Providers, Invocation Rule, Credential and Configuration… and Workflow: Connect or Create…, plus 2 more sections
  • Reaches zc.reg.163.com and ssl.zc.qq.com

What it does

This skill supports NetEase, Tencent, Sina, Alibaba, and Google personal mail domains, each needing either a 16-character authorization or app code, or for Alibaba an existing account's login password. Enterprise mailboxes, custom domains, and Microsoft mailboxes are explicitly unsupported, and it won't improvise raw IMAP or SMTP as a workaround.

It keeps sensitive fields such as the auth code, password, and phone number out of its public configuration file and redacted from API responses, resolving the encrypted credential into a managed connection only at runtime. It never reads, decrypts, prints, or searches logs for a stored secret, relying instead on its documented connect-or-create workflow.

When your agent uses it

  • Connecting a personal mailbox for the first time
  • Searching, reading, or organizing email in a connected mailbox
  • Sending, replying to, or forwarding a message

Example prompts

  • “Connect my QQ mailbox using my authorization code.”
  • “Search my inbox for messages from my accountant this month.”
  • “Reply to the latest email from my landlord and archive the thread.”

Requirements

  • A configured mailbox connection through the bundled mail server
  • A supported mail provider authorization code or app password

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Read public mailbox state
  2. After successful registration

What it can do on your machine

Read from SKILL.md and the folder at commit f389534. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • zc.reg.163.com
    • ssl.zc.qq.com
    • mail.sina.com.cn
    • mail.sina.cn
    • accounts.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Mailbox Operations Hub loads about 2.6k tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 1,218 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from agentscope-ai/QwenPaw at commit f389534, republished under its Apache-2.0 licence (© agentscope-ai). 1,218 words, ~2,569 tokens.

Download SKILL.mdSave it as .claude/skills/mailbox/SKILL.md (or your agent's skills folder).
name
mailbox
description
Use this skill whenever the user needs ANY mailbox/email operation — checking, reading, searching, sending, replying, forwarding, organizing or deleting email, managing threads, connecting a personal mailbox, or registering a new mailbox. This skill is the single entry point for email tasks and orchestrates qwenpawmail-mcp for nine supported personal-mail domains.
metadata.builtin_skill_version
1.3

Mailbox Operations (qwenpawmail-mcp)

Use qwenpawmail-mcp to connect or register a mailbox and perform email operations.

Supported Providers

The managed QwenPaw mailbox workflow supports these nine mail domains:

ProviderDomainsLogin credential
NetEase163.com, 126.com, yeah.net16-character authorization code
Tencentqq.com, foxmail.com16-character authorization code
Sinasina.com, sina.cn16-character authorization code
Alibabaaliyun.comMailbox login password; existing accounts only
Googlegmail.com16-character app password after enabling 2-Step Verification

Enterprise mailboxes, custom domains, and Microsoft mailboxes are not supported by the current managed workflow. Do not try enterprise provider overrides or custom IMAP/SMTP hosts. Ask the user to choose one of the supported personal domains instead.

create_mailbox provides built-in registration guidance only for 163.com, 126.com, yeah.net, qq.com, and foxmail.com. Other supported domains require their official registration flow. New aliyun.com registration is unavailable; only existing accounts can be connected.

Invocation Rule

For any email operation, use this skill as the entry point. Do not invent another email workflow or bypass qwenpawmail-mcp with raw IMAP/SMTP commands.

Credential and Configuration Model

agent.json contains only public mailbox configuration. Its expected mail shape is:

json
{
  "mail": {
    "is_new_account": false,
    "credential": {
      "name": "myaccount",
      "domain": "163.com",
      "provider": ""
    },
    "push": {
      "mode": "off",
      "rules": [],
      "poll_interval_seconds": 120,
      "access_control_enabled": false
    }
  }
}

The sensitive fields auth_code, password, and phone_number are intentionally absent from agent.json and redacted from Agent API responses. The provider credential represented by auth_code is stored encrypted after it is configured. Registration passwords and phone numbers are entered only on the provider page and are not stored by the current QwenPaw workflow. The absence of auth_code from public configuration does not mean that the user did not configure it.

QwenPaw resolves the encrypted provider credential into the managed DriverCard only at runtime. Never read, decrypt, print, copy, or modify credentials.yaml, and never search files or logs for a secret. Use the workflows below.

Workflow: Connect or Create the Mailbox Account

Step 1 — Read public mailbox state

Read mail.is_new_account, mail.credential.name, and mail.credential.domain from agent.json. Treat provider as empty for every currently supported personal domain.

If mail is missing, ask the user to configure Email Management in the QwenPaw Agent Settings UI before continuing.

Step 2a — is_new_account is false: manage an existing mailbox
  1. Call check_auth directly. The managed DriverCard already receives the stored email credential through a runtime credential reference; do not look it up in agent.json and do not call set_credentials merely because secret fields are absent.
  2. If check_auth succeeds, perform the requested mailbox operation.
  3. If credentials are missing or invalid, ask the user to edit this agent in QwenPaw, choose Manage your personal mailbox, enter the mailbox credential again, and save. Retry check_auth after the agent reloads.
  4. If the user explicitly supplies an email and credential in the current conversation, set_credentials may be used as a temporary session-only override, followed by check_auth. It does not update the encrypted QwenPaw configuration and is lost when the MCP process restarts.

For temporary set_credentials, pass the full email and the provider-specific credential in the auth_code parameter. For aliyun.com, that parameter contains the login password; for the other supported domains, it contains the 16-character authorization code or app password.

Step 2b — is_new_account is true: register a dedicated mailbox

Use the public username and domain from agent.json. If the username is blank, let create_mailbox generate one or agree on one with the user.

Registration passwords and phone numbers are entered on the provider page and are deliberately unavailable to the Agent. Do not try to recover them from files. The optional credential field in the QwenPaw dedicated-mailbox form is only for the final provider authorization code, app password, or mailbox login password after registration. Use one of these paths:

Preferred path — visible browser registration
  1. For NetEase or Tencent domains, call create_mailbox(domain, username) first to validate the username and obtain current provider guidance.
  2. Open the provider's official registration page in a visible browser.
  3. When the page requests a password, phone number, CAPTCHA, SMS code, or other identity verification, ask the user to enter it directly in the visible browser. If the user explicitly provides a value for this task, use it only for the current registration and never persist or repeat it.
  4. Keep the browser open while waiting for user action, then continue after confirmation.

Official registration entry points:

DomainRegistration entryNotes
163.com, 126.com, yeah.nethttps://zc.reg.163.com/regInitializedShared NetEase flow; phone verification required
qq.com, foxmail.comhttps://ssl.zc.qq.com/v3/index-chs.htmlQQ registration; phone verification required
sina.comhttps://mail.sina.com.cn/register/weixin.phpWeChat-authorized registration
sina.cnhttps://mail.sina.cn/register/regmail.phpPhone/SMS registration
gmail.comhttps://accounts.google.com/signupEnable 2-Step Verification, then create an app password
aliyun.comUnavailableNew personal registrations are closed; use an existing account

Consider registration successful only after a clear success message or successful inbox access. If the final username differs from the requested one, report the reason and final address.

Show full SKILL.md (451 more words)Show less
Fallback path — user-completed registration

For NetEase or Tencent domains, call create_mailbox(domain, username) and relay its alternatives, registration URL, and steps. Ask the user to complete all password, phone, CAPTCHA, and SMS steps in their own browser.

For Sina or Gmail, direct the user to the official entry above. For aliyun.com, explain that a new account cannot be registered and ask the user to choose another supported domain.

Step 3 — After successful registration
  1. Do not write an authorization code, password, or phone number into agent.json.
  2. Ask the user to edit the agent in the QwenPaw Agent Settings UI and keep Provision a dedicated mailbox selected. Enter the final mailbox name and the optional provider credential shown for that domain, then save. The field accepts a 16-character authorization code/app password for NetEase, Tencent, Sina, or Gmail, and a login password for a provider that uses one. QwenPaw will automatically set is_new_account to false, store the secret in encrypted form, synchronize the managed DriverCard, and reload the agent.
  3. After reload, call check_auth. Do not run other mail tools until it succeeds.
  4. Read CONTACTS.md before contact-dependent work.

Available Tools

Read-Only Tools
ToolPurpose
list_foldersList all mailbox folders
list_messagesList message envelopes in a folder with pagination
get_messageFetch one message by folder and UID
get_attachmentGet an attachment by filename or index
search_messagesSearch by keyword, sender, or date range
check_authVerify fresh IMAP and SMTP logins using the current runtime credential
create_mailboxReturn registration guidance for supported NetEase/Tencent domains
list_threadsList conversation threads with incremental sync
search_threadsSearch conversation threads
get_threadGet all messages in one thread
get_mailbox_statsGet recent mailbox statistics
Write Tools
ToolPurpose
send_messageSend a plain-text email with to/cc/bcc
reply_messageReply with proper threading headers
forward_messageForward a message as an RFC 822 attachment
mark_messagesMark messages read/unread/flagged/unflagged
move_messageMove a message to another folder
create_folderCreate a mailbox folder
set_credentialsSet a temporary in-memory credential for this MCP process
clear_credentialsClear the temporary override and fall back to injected startup credentials
update_threadAdd or remove custom thread labels
Destructive Tools
ToolPurpose
delete_messagePermanently delete one message
delete_threadMove a whole thread to trash

Safety and Reliability Notes

  • Never guess or expose an authorization code, password, phone number, CAPTCHA, or SMS code.
  • Never interpret redacted secret fields as empty credentials; verify with check_auth.
  • Never place secrets in agent.json, DriverCard YAML, CONTACTS.md, logs, or chat summaries.
  • Confirm with the user before delete_message or delete_thread.
  • Message UIDs are folder-scoped and can change. Refresh with list_messages or search_messages immediately before acting.
  • After any runtime or UI credential change, call check_auth first.
  • Update CONTACTS.md when the user wants newly discovered contact information retained, but never store credentials there.

© agentscope-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in src/qwenpaw/agents/skills/mailbox-en of agentscope-ai/QwenPaw.

Open the folder on GitHubat commit f389534

Compare with similar skills

Mailbox Operations Hub next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mailbox Operations Hub compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mailbox Operations Hub this skillagentscope-ai/QwenPaw35k—~2.6kAutomated safety check: PassApache-2.0
Gmail Query Syntaxprovos/ironcurtain613—~971Automated safety check: PassApache-2.0
Connectorsautonomous-ai/Physical-AI-Operating-System381—~10kAutomated safety check: NotesApache-2.0
Email CheckAgriciDaniel/claude-email129—~2.4kAutomated safety check: PassMIT
Add Gmailsbusso/claudeclaw194—~1.9kAutomated safety check: PassMIT
Performance Patternss-morgan-jeffries/apple-mail-fast-mcp104—~1.5kAutomated safety check: PassMIT

Similar skills

  • Gmail Query Syntax

    provos/ironcurtain

    Reference for Gmail's search query syntax — operators like is:sent, newerthan:, from:, has:attachment, label:, and how they compose.

    613 GitHub stars~971 tokensUpdated yesterday
    Productivity & AutomationAuto-check passed
  • Connectors

    autonomous-ai/Physical-AI-Operating-System

    Discover and use linked third-party services (Gmail, Google Calendar, Google Drive, Notion, Figma, Asana, Linear, GitHub, Ahrefs, Facebook Fan Page and others).

    381 GitHub stars~10k tokensUpdated today
    Productivity & AutomationAuto-check: notes
  • Email Check

    AgriciDaniel/claude-email

    Intelligent inbox triage that connects to Gmail or Outlook, scores emails by importance (0-100) using sender recognition, urgency keywords, thread depth, time sensitivity, and business relevance…

    129 GitHub stars~2.4k tokensUpdated 4 mo ago
    Productivity & AutomationAuto-check passed
  • Add Gmail

    sbusso/claudeclaw

    Add Gmail integration to ClaudeClaw. An agent skill from sbusso/claudeclaw.

    194 GitHub stars~1.9k tokensUpdated 1 mo ago
    Productivity & AutomationAuto-check passed
  • Performance Patterns

    s-morgan-jeffries/apple-mail-fast-mcp

    A skill your agent uses when optimizing Apple Mail MCP operations, diagnosing slow queries, adding new filtering logic, or modifying how data is fetched from Mail.app.

    104 GitHub stars~1.5k tokensUpdated 29 days ago
    Productivity & AutomationAuto-check passed
  • Setup Lanes Link

    lanes-sh/app

    A skill your agent uses when installing or standing up Lanes Link, the self-hostable MCP endpoint that gives an agent someone's own accounts, memory, tasks, assets, skills, identity and vault.

    273 GitHub stars~2.3k tokensUpdated 2 days ago
    Productivity & AutomationAuto-check passed

More from agentscope-ai/QwenPaw

All 20 skills in this repo
  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    35k GitHub starsUsed in 6 repos~4.2k tokens
    Auto-check passed
  • Make Skill

    agentscope-ai/QwenPaw

    Turns reusable decisions, templates or workflows from the current conversation into a new workspace skill through plan, approval, draft, validation and publication.

    35k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • QwenPaw Make Skill

    agentscope-ai/QwenPaw

    Creates a focused workspace skill from the current conversation in QwenPaw, moving through a planning, approval, drafting, validation and publishing script pipeline.

    35k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • QwenPaw Scheduled Tasks

    agentscope-ai/QwenPaw

    Creates and manages scheduled or recurring jobs with the qwenpaw cron commands, always tied to an explicit agent ID and a confirmed target channel.

    35k GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • DOCX Creation and Editing

    agentscope-ai/QwenPaw

    Creates, reads and edits Word .docx files, including tracked changes and comments, using docx-js for new files and XML editing for existing ones.

    35k GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • OMP Sub-Agent Role Presets

    agentscope-ai/QwenPaw

    Gives the allowed_tools and skills preset for each OMP sub-agent role, to apply when calling spawn_subagent.

    35k GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Questions about Mailbox Operations Hub

What does Mailbox Operations Hub do?

Connects, registers, and operates a personal mailbox, reading, searching, sending, and organizing, through a managed mail server for nine domains. This skill supports NetEase, Tencent, Sina, Alibaba, and Google personal mail domains, each needing either a 16-character authorization or app code, or for Alibaba an existing account's login password. Enterprise mailboxes, custom domains, and Microsoft mailboxes are explicitly unsupported, and it won't improvise raw IMAP or SMTP as a workaround.

When should I use Mailbox Operations Hub?

Mailbox Operations Hub fits situations like: connecting a personal mailbox for the first time; searching, reading, or organizing email in a connected mailbox; sending, replying to, or forwarding a message.

How do I install Mailbox Operations Hub in Claude Code?

Run `npx skills add agentscope-ai/QwenPaw --skill mailbox -a claude-code`. Or copy the skill folder (src/qwenpaw/agents/skills/mailbox-en in agentscope-ai/QwenPaw) into .claude/skills/mailbox in your project. Claude Code loads it when a task matches its description.

How do I install Mailbox Operations Hub in Codex?

Run `npx skills add agentscope-ai/QwenPaw --skill mailbox -a codex`. Or copy the skill folder (src/qwenpaw/agents/skills/mailbox-en in agentscope-ai/QwenPaw) into .agents/skills/mailbox in your project. Codex loads it when a task matches its description.

Can I use Mailbox Operations Hub in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agentscope-ai/QwenPaw --skill mailbox -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mailbox, .gemini/skills/mailbox, .github/skills/mailbox and .opencode/skills/mailbox in your project.

What does Mailbox Operations Hub need to run?

SKILL.md names no scripts, command-line tools or credentials: Mailbox Operations Hub is instructions for the agent only. Our summary lists: A configured mailbox connection through the bundled mail server; A supported mail provider authorization code or app password.

Does Mailbox Operations Hub access the network?

SKILL.md names 5 domains. In commands or code: zc.reg.163.com, ssl.zc.qq.com, mail.sina.com.cn, mail.sina.cn and accounts.google.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Mailbox Operations Hub safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Mailbox Operations Hub use?

Mailbox Operations Hub is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Mailbox Operations Hub use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Mailbox Operations Hub?

Skills that share tags, products or a category with Mailbox Operations Hub: Gmail Query Syntax (provos/ironcurtain, 613 stars), Connectors (autonomous-ai/Physical-AI-Operating-System, 381 stars), Email Check (AgriciDaniel/claude-email, 129 stars) and Add Gmail (sbusso/claudeclaw, 194 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mailbox Operations Hub?

agentscope-ai (a GitHub organization) maintains it in agentscope-ai/QwenPaw, which has 35,493 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 8, 2026.

Source: agentscope-ai/QwenPaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.