Agent skill

QwenPaw Mailbox Operations

by agentscope-ai in agentscope-ai/QwenPaw

Single entry point for email tasks in QwenPaw through qwenpawmail-mcp: read, search, send, reply, organize, and bind or register a personal mailbox.

Apache-2.0Auto-check passedProductivity & Automation

SKILL.md written in Chinese; this summary is our English description.

Install QwenPaw Mailbox Operations

skills CLI
$ npx skills add agentscope-ai/QwenPaw --skill mailbox -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install agentscope-ai/QwenPaw mailbox --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/agentscope-ai/QwenPaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/qwenpaw/agents/skills/mailbox-zh .claude/skills/mailbox && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mailbox
GitHub stars
36k
Token cost
~1.3k tokens
SKILL.md length
313 words
Files
1
Skills in repo
20
Repo updated
First seen
Licence
Apache-2.0

At a glance

Single entry point for email tasks in QwenPaw through qwenpawmail-mcp: read, search, send, reply, organize, and bind or register a personal mailbox.

  • Works in 4 steps: 直接调用 check_auth。托管 DriverCard… → check_auth 成功后,执行用户要求的邮件操作。 → 如果凭据缺失或失效,请用户在 QwenPaw… → …
  • Reading or searching the inbox of a bound personal mailbox
  • SKILL.md covers 支持的邮箱服务商, 调用规则, 凭据与配置模型 and 工作流程:绑定或注册邮箱账号, plus 2 more sections
  • Reaches zc.reg.163.com and ssl.zc.qq.com

What it does

This skill is the only route for mail work in QwenPaw: viewing, reading, searching, sending, replying, forwarding, organizing and deleting messages, managing threads, and binding a personal mailbox or registering a new one. Everything goes through qwenpawmail-mcp, and the agent must not invent other mail flows or run raw IMAP or SMTP commands. It supports 9 personal domains from NetEase, Tencent, Sina, Aliyun and Gmail, but not enterprise mailboxes, custom domains or Microsoft mail.

Credentials get careful handling. The agent.json file holds only public mailbox settings, secrets such as auth_code, password and phone number are kept out of it, and the agent must never read, decrypt, print or edit credentials.yaml. For an existing account the agent calls check_auth, asks you to update credentials in QwenPaw settings if they are missing, and uses set_credentials only as a session-level override. New NetEase or Tencent addresses get guided sign-up in a visible browser where you type passwords, phone numbers and codes yourself. Aliyun accepts existing accounts only. The skill text is in Chinese.

When your agent uses it

  • Reading or searching the inbox of a bound personal mailbox
  • Sending, replying to or forwarding an email through QwenPaw
  • Binding an existing mailbox or registering a new 163 or QQ address

Example prompts

  • “Search my mailbox for emails from the bank about the latest statement.”
  • “Reply to the newest email from my landlord and confirm Friday for the repair.”
  • “Register a new qq.com mailbox for this agent.”

Requirements

  • The qwenpawmail-mcp server
  • A QwenPaw agent with mailbox settings in agent.json
  • A mailbox on a supported provider, such as 163.com, qq.com or gmail.com
  • A visible browser for new mailbox sign-up

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. 直接调用 check_auth。托管 DriverCard 已经通过运行时凭据引用获取加密存储中的邮箱凭据;不要从 agent.json 查找凭据,也不要因为看不到 secret 字段就调用 set_credentials。
  2. check_auth 成功后,执行用户要求的邮件操作。
  3. 如果凭据缺失或失效,请用户在 QwenPaw 中编辑当前智能体,选择“管理你的个人邮箱”,重新填写邮箱凭据并保存。智能体重载后再次调用 check_auth。
  4. 如果用户在当前对话中明确提供邮箱地址和凭据,可以调用 set_credentials 作为仅限当前会话的临时覆盖,随后调用 check_auth。它不会更新 QwenPaw 的加密配置,MCP 进程重启后即失效。

What it can do on your machine

Read from SKILL.md and the folder at commit d7a0f50. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • zc.reg.163.com
    • ssl.zc.qq.com
    • mail.sina.com.cn
    • mail.sina.cn
    • accounts.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

QwenPaw Mailbox Operations loads about 1.3k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 313 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from agentscope-ai/QwenPaw at commit d7a0f50, republished under its Apache-2.0 licence (© agentscope-ai). 313 words, ~1,280 tokens.

Download SKILL.mdSave it as .claude/skills/mailbox/SKILL.md (or your agent's skills folder).
name
mailbox
description
当用户需要任何邮箱/邮件操作时使用此技能——包括查看、阅读、搜索、发送、回复、转发、整理或删除邮件,管理会话线程,绑定个人邮箱或注册新邮箱。此技能是邮件任务的统一且唯一入口,通过 qwenpawmail-mcp 编排操作,当前支持 9 个个人邮箱域名。
metadata.builtin_skill_version
1.3

邮箱操作 (qwenpawmail-mcp)

使用 qwenpawmail-mcp 绑定或注册邮箱并执行邮件操作。

支持的邮箱服务商

QwenPaw 托管邮箱流程当前支持以下 9 个邮箱域名:

服务商域名登录凭据
网易163.com、126.com、yeah.net16 位授权码
腾讯qq.com、foxmail.com16 位授权码
新浪sina.com、sina.cn16 位授权码
阿里aliyun.com邮箱登录密码;仅支持已有账号
Googlegmail.com开启两步验证后生成的 16 位应用专用密码

当前托管流程不支持企业邮箱、自定义域名和 Microsoft 邮箱。

create_mailbox 仅为 163.com、126.com、yeah.net、qq.com 和 foxmail.com 提供内置注册引导。其他受支持域名需走服务商官方注册流程。aliyun.com 已关闭个人邮箱新注册,只能绑定已有账号。

调用规则

任何邮件操作都必须从此技能进入。不要自行编造其他邮件流程,也不要绕过 qwenpawmail-mcp 直接执行原始 IMAP/SMTP 命令。

凭据与配置模型

agent.json 只保存公开邮箱配置。mail 的预期结构为:

json
{
  "mail": {
    "is_new_account": false,
    "credential": {
      "name": "myaccount",
      "domain": "163.com",
      "provider": ""
    },
    "push": {
      "mode": "off",
      "rules": [],
      "poll_interval_seconds": 120,
      "access_control_enabled": false
    }
  }
}

敏感字段 auth_code、password 和 phone_number 会被刻意排除在 agent.json 之外,Agent API 响应也不会返回它们。服务商凭据统一通过 auth_code 表示,配置后会被加密保存;注册密码和手机号只在对应邮箱的注册网页内填写,当前 QwenPaw 流程不会保存。公开配置中看不到 auth_code 并不表示用户没有配置凭据。

QwenPaw 仅在运行时通过托管 DriverCard 解析加密的服务商凭据。绝不要读取、解密、打印、复制或修改 credentials.yaml,也不要在文件或日志中搜索 secret。请严格使用下述流程。

工作流程:绑定或注册邮箱账号

第 1 步 — 读取公开邮箱状态

从 agent.json 读取 mail.is_new_account、mail.credential.name 和 mail.credential.domain。当前支持的个人邮箱域名对应的 provider 应为空字符串。

如果不存在 mail,请用户先在 QwenPaw 的智能体设置界面配置“邮箱管理”。

第 2a 步 — is_new_account 为 false:管理已有邮箱
  1. 直接调用 check_auth。托管 DriverCard 已经通过运行时凭据引用获取加密存储中的邮箱凭据;不要从 agent.json 查找凭据,也不要因为看不到 secret 字段就调用 set_credentials。
  2. check_auth 成功后,执行用户要求的邮件操作。
  3. 如果凭据缺失或失效,请用户在 QwenPaw 中编辑当前智能体,选择“管理你的个人邮箱”,重新填写邮箱凭据并保存。智能体重载后再次调用 check_auth。
  4. 如果用户在当前对话中明确提供邮箱地址和凭据,可以调用 set_credentials 作为仅限当前会话的临时覆盖,随后调用 check_auth。它不会更新 QwenPaw 的加密配置,MCP 进程重启后即失效。

临时调用 set_credentials 时,传入完整邮箱地址,并把服务商所需凭据放入名为 auth_code 的参数。对于 aliyun.com,该参数实际填写登录密码;其他受支持域名填写 16 位授权码或应用专用密码。

第 2b 步 — is_new_account 为 true:注册专属邮箱

使用 agent.json 中公开的用户名和域名。如果用户名为空,让 create_mailbox 生成用户名,或先与用户确定用户名。

注册密码和手机号只在对应邮箱的注册网页内填写,Agent 无法读取。不要尝试从文件恢复它们。QwenPaw 专属邮箱表单中的可选凭据字段仅用于注册完成后的最终授权码、应用专用密码或邮箱登录密码。请选择以下路径之一:

首选路径 — 可视浏览器注册
  1. 对网易或腾讯域名,先调用 create_mailbox(domain, username) 校验用户名并获取当前服务商引导。
  2. 在可视浏览器中打开服务商官方注册页面。
  3. 页面要求密码、手机号、验证码、短信验证码或其他身份验证时,请用户直接在可视浏览器中填写。如果用户明确为本次任务提供了某个值,只能在本次注册中使用,绝不落盘或复述。
  4. 等待用户操作时保持浏览器开启;用户确认完成后继续。

官方注册入口:

域名注册入口说明
163.com、126.com、yeah.nethttps://zc.reg.163.com/regInitialized网易统一流程,需要手机验证
qq.com、foxmail.comhttps://ssl.zc.qq.com/v3/index-chs.htmlQQ 注册流程,需要手机验证
sina.comhttps://mail.sina.com.cn/register/weixin.php微信授权注册
sina.cnhttps://mail.sina.cn/register/regmail.php手机短信注册
gmail.comhttps://accounts.google.com/signup注册后开启两步验证并创建应用专用密码
aliyun.com不可用已关闭个人邮箱新注册,只能使用已有账号

只有看到明确的注册成功提示或成功进入收件箱后,才能判定注册成功。如果最终用户名与原计划不同,应报告原因和最终邮箱地址。

备选路径 — 用户自行完成注册

对于网易或腾讯域名,调用 create_mailbox(domain, username),把返回的备选用户名、注册链接和步骤告知用户。请用户在自己的浏览器中完成密码、手机号、验证码和短信验证等所有敏感步骤。

对于新浪或 Gmail,引导用户使用上方官方入口。对于 aliyun.com,说明无法注册新账号,并请用户选择其他受支持域名。

第 3 步 — 注册成功后
  1. 不要把授权码、密码或手机号写入 agent.json。
  2. 请用户在 QwenPaw 智能体设置界面编辑该智能体,保持选择“为智能体配备专属邮箱”,填写最终邮箱名以及该域名对应的可选凭据,然后保存。网易、腾讯、新浪或 Gmail 填写 16 位授权码/应用专用密码;使用登录密码的服务商则填写邮箱登录密码。QwenPaw 会自动将 is_new_account 设为 false、加密保存 secret、同步托管 DriverCard 并重载智能体。
  3. 重载后调用 check_auth;验证成功前不要调用其他邮件工具。
  4. 涉及联系人时先读取 CONTACTS.md。

可用工具

只读工具
工具用途
list_folders列出所有邮箱文件夹
list_messages分页列出文件夹中的邮件元数据
get_message按文件夹和 UID 获取单封邮件
get_attachment按文件名或索引获取附件
search_messages按关键词、发件人或日期范围搜索邮件
check_auth使用当前运行时凭据重新验证 IMAP 和 SMTP 登录
create_mailbox返回网易/腾讯受支持域名的注册引导
list_threads增量同步并列出会话线程
search_threads搜索会话线程
get_thread获取一个线程中的所有邮件
get_mailbox_stats获取近期邮箱统计
写操作工具
工具用途
send_message发送带 to/cc/bcc 的纯文本邮件
reply_message使用正确的线程头回复邮件
forward_message以 RFC 822 附件形式转发邮件
mark_messages标记已读/未读/星标/取消星标
move_message将邮件移动到其他文件夹
create_folder创建邮箱文件夹
set_credentials为当前 MCP 进程设置临时内存凭据
clear_credentials清除临时覆盖并回退到启动时注入的凭据
update_thread添加或移除线程自定义标签
破坏性工具
工具用途
delete_message永久删除单封邮件
delete_thread将整个线程移入垃圾箱

安全性与可靠性注意事项

  • 绝不猜测或暴露授权码、密码、手机号、验证码或短信验证码。
  • 绝不能把已脱敏的 secret 字段理解为空凭据;应通过 check_auth 验证。
  • 绝不把 secret 写入 agent.json、DriverCard YAML、CONTACTS.md、日志或对话总结。
  • 调用 delete_message 或 delete_thread 前必须向用户确认。
  • 邮件 UID 属于具体文件夹且可能变化;操作前立即用 list_messages 或 search_messages 刷新。
  • 通过界面或运行时修改凭据后,必须先调用 check_auth。
  • 用户希望保留新联系人信息时更新 CONTACTS.md,但绝不能在其中保存凭据。

© agentscope-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in src/qwenpaw/agents/skills/mailbox-zh of agentscope-ai/QwenPaw.

Open the folder on GitHubat commit d7a0f50

Compare with similar skills

QwenPaw Mailbox Operations next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

QwenPaw Mailbox Operations compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
QwenPaw Mailbox Operations this skillagentscope-ai/QwenPaw36k—~1.3kAutomated safety check: PassApache-2.0
Gmail Query Syntaxprovos/ironcurtain612—~971Automated safety check: PassApache-2.0
Email CheckAgriciDaniel/claude-email130—~2.4kAutomated safety check: PassMIT
Connectorsautonomous-ai/Physical-AI-Operating-System381—~10kAutomated safety check: NotesApache-2.0
Add Gmailsbusso/claudeclaw194—~1.9kAutomated safety check: PassMIT
Performance Patternss-morgan-jeffries/apple-mail-fast-mcp104—~1.5kAutomated safety check: PassMIT

Similar skills

  • Gmail Query Syntax

    provos/ironcurtain

    Reference for Gmail's search query syntax — operators like is:sent, newerthan:, from:, has:attachment, label:, and how they compose.

    612 GitHub stars~971 tokensUpdated 2 days ago
    Productivity & AutomationAuto-check passed
  • Email Check

    AgriciDaniel/claude-email

    Intelligent inbox triage that connects to Gmail or Outlook, scores emails by importance (0-100) using sender recognition, urgency keywords, thread depth, time sensitivity, and business relevance…

    130 GitHub stars~2.4k tokensUpdated 4 mo ago
    Productivity & AutomationAuto-check passed
  • Connectors

    autonomous-ai/Physical-AI-Operating-System

    Discover and use linked third-party services (Gmail, Google Calendar, Google Drive, Notion, Figma, Asana, Linear, GitHub, Ahrefs, Facebook Fan Page and others).

    381 GitHub stars~10k tokensUpdated today
    Productivity & AutomationAuto-check: notes
  • Add Gmail

    sbusso/claudeclaw

    Add Gmail integration to ClaudeClaw. An agent skill from sbusso/claudeclaw.

    194 GitHub stars~1.9k tokensUpdated 1 mo ago
    Productivity & AutomationAuto-check passed
  • Performance Patterns

    s-morgan-jeffries/apple-mail-fast-mcp

    A skill your agent uses when optimizing Apple Mail MCP operations, diagnosing slow queries, adding new filtering logic, or modifying how data is fetched from Mail.app.

    104 GitHub stars~1.5k tokensUpdated 29 days ago
    Productivity & AutomationAuto-check passed
  • Setup Lanes Link

    lanes-sh/app

    A skill your agent uses when installing or standing up Lanes Link, the self-hostable MCP endpoint that gives an agent someone's own accounts, memory, tasks, assets, skills, identity and vault.

    273 GitHub stars~2.3k tokensUpdated 2 days ago
    Productivity & AutomationAuto-check passed

More from agentscope-ai/QwenPaw

All 20 skills in this repo
  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    36k GitHub starsUsed in 6 repos~4.2k tokens
    Auto-check passed
  • Make Skill

    agentscope-ai/QwenPaw

    Turns reusable decisions, templates or workflows from the current conversation into a new workspace skill through plan, approval, draft, validation and publication.

    36k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • QwenPaw Make Skill

    agentscope-ai/QwenPaw

    Creates a focused workspace skill from the current conversation in QwenPaw, moving through a planning, approval, drafting, validation and publishing script pipeline.

    36k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • QwenPaw Scheduled Tasks

    agentscope-ai/QwenPaw

    Creates and manages scheduled or recurring jobs with the qwenpaw cron commands, always tied to an explicit agent ID and a confirmed target channel.

    36k GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • DOCX Creation and Editing

    agentscope-ai/QwenPaw

    Creates, reads and edits Word .docx files, including tracked changes and comments, using docx-js for new files and XML editing for existing ones.

    36k GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Mailbox Operations Hub

    agentscope-ai/QwenPaw

    Connects, registers, and operates a personal mailbox, reading, searching, sending, and organizing, through a managed mail server for nine domains.

    36k GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Questions about QwenPaw Mailbox Operations

What does QwenPaw Mailbox Operations do?

Single entry point for email tasks in QwenPaw through qwenpawmail-mcp: read, search, send, reply, organize, and bind or register a personal mailbox. This skill is the only route for mail work in QwenPaw: viewing, reading, searching, sending, replying, forwarding, organizing and deleting messages, managing threads, and binding a personal mailbox or registering a new one. Everything goes through qwenpawmail-mcp, and the agent must not invent other mail flows or run raw IMAP or SMTP commands.

When should I use QwenPaw Mailbox Operations?

QwenPaw Mailbox Operations fits situations like: reading or searching the inbox of a bound personal mailbox; sending, replying to or forwarding an email through QwenPaw; binding an existing mailbox or registering a new 163 or QQ address.

How do I install QwenPaw Mailbox Operations in Claude Code?

Run `npx skills add agentscope-ai/QwenPaw --skill mailbox -a claude-code`. Or copy the skill folder (src/qwenpaw/agents/skills/mailbox-zh in agentscope-ai/QwenPaw) into .claude/skills/mailbox in your project. Claude Code loads it when a task matches its description.

How do I install QwenPaw Mailbox Operations in Codex?

Run `npx skills add agentscope-ai/QwenPaw --skill mailbox -a codex`. Or copy the skill folder (src/qwenpaw/agents/skills/mailbox-zh in agentscope-ai/QwenPaw) into .agents/skills/mailbox in your project. Codex loads it when a task matches its description.

Can I use QwenPaw Mailbox Operations in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agentscope-ai/QwenPaw --skill mailbox -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mailbox, .gemini/skills/mailbox, .github/skills/mailbox and .opencode/skills/mailbox in your project.

What does QwenPaw Mailbox Operations need to run?

SKILL.md names no scripts, command-line tools or credentials: QwenPaw Mailbox Operations is instructions for the agent only. Our summary lists: The qwenpawmail-mcp server; A QwenPaw agent with mailbox settings in agent.json; A mailbox on a supported provider, such as 163.com, qq.com or gmail.com; A visible browser for new mailbox sign-up.

Does QwenPaw Mailbox Operations access the network?

SKILL.md names 5 domains. In commands or code: zc.reg.163.com, ssl.zc.qq.com, mail.sina.com.cn, mail.sina.cn and accounts.google.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is QwenPaw Mailbox Operations safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does QwenPaw Mailbox Operations use?

QwenPaw Mailbox Operations is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does QwenPaw Mailbox Operations use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to QwenPaw Mailbox Operations?

Skills that share tags, products or a category with QwenPaw Mailbox Operations: Gmail Query Syntax (provos/ironcurtain, 612 stars), Email Check (AgriciDaniel/claude-email, 130 stars), Connectors (autonomous-ai/Physical-AI-Operating-System, 381 stars) and Add Gmail (sbusso/claudeclaw, 194 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains QwenPaw Mailbox Operations?

agentscope-ai (a GitHub organization) maintains it in agentscope-ai/QwenPaw, which has 35,521 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 9, 2026.

Source: agentscope-ai/QwenPaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.