Agent skill

Mailbox Bridge

by WrongStack in WrongStack/WrongStack

A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…

MITAuto-check passed

Install Mailbox Bridge

skills CLI
$ npx skills add WrongStack/WrongStack --skill mailbox-bridge -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install WrongStack/WrongStack mailbox-bridge --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/core/skills/mailbox-bridge .claude/skills/mailbox-bridge && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mailbox-bridge
GitHub stars
368
Token cost
~3.9k tokens
SKILL.md length
1,684 words
Files
2 (incl. references)
Skills in repo
38
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…

  • External coding agents (Claude Code
  • SKILL.md covers Overview, When to use this skill, When NOT to use this skill and Setup, plus 10 more sections
  • Needs WRONGSTACK_MAILBOX_TOKEN
  • Custom scripts) need to participate in the projects shared WrongStack mailbox

What it does

Mailbox Bridge is an agent skill from WrongStack/WrongStack. Use this skill when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox", "let Claude Code read the mailbox", "external agent mailbox", "mailbox bridge", or "HTTP mailbox bridge". Starts a loopback HTTP façade over the same GlobalMailbox that WrongStack-internal agents already share, so any agent with curl or fetch can read, send, and acknowledge messages.

Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/examples.md`).

The repository describes itself as: An AI coding agent that reads your code, edits files, runs commands, and reasons through bugs — across a terminal REPL, a full-screen TUI, and a browser UI, while you keep your… The licence is MIT.

When your agent uses it

  • External coding agents (Claude Code
  • Custom scripts) need to participate in the projects shared WrongStack mailbox
  • A user asks to expose the mailbox
  • Let Claude Code read the mailbox

Example prompts

  • “s shared WrongStack mailbox, or when a user asks to”
  • “let Claude Code read the mailbox”
  • “external agent mailbox”
  • “/mailbox-bridge”

Requirements

  • A credential in WRONGSTACK_MAILBOX_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit ec76a20. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • WRONGSTACK_MAILBOX_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Mailbox Bridge loads about 3.9k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 122 tokens; SKILL.md has 1,684 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~122
When it runs · the whole SKILL.md, loaded when a task matches
~3.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from WrongStack/WrongStack at commit ec76a20, republished under its MIT licence (© WrongStack). 1,684 words, ~3,909 tokens.

Download SKILL.mdSave it as .claude/skills/mailbox-bridge/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
mailbox-bridge
description
Use this skill when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox", "let Claude Code read the mailbox", "external agent mailbox", "mailbox bridge", or "HTTP mailbox bridge". Starts a loopback HTTP façade over the same GlobalMailbox that WrongStack-internal agents already share, so any agent with curl or fetch can read, send, and acknowledge messages.
version
1.1.0
required-capabilities
execution.shell
optional-capabilities
web.research

Mailbox Bridge — Expose the Shared Mailbox to External Agents

Bundled skill. This file is shipped with @wrongstack/core and auto-discovered via bundledSkillsDir. To pin it to a specific project, run wstack skill install <path-to-this-file> once — the project-level manifest at ~/.wrongstack/projects/<slug>/installed-skills.json will record that override.

Overview

WrongStack-internal agents (CLI, TUI, WebUI, ACP) already share one project-level mailbox, a SQLite store at ~/.wrongstack/projects/<slug>/_mailbox.sqlite. This skill starts a thin loopback HTTP server that wraps that exact same GlobalMailbox so external coding agents — Claude Code, Aider, Continue, a user's own scripts — can read and send messages on the same channel without touching the store directly.

┌────────────────────────────────────────────────────────────────────┐
│                    WrongStack project dir                          │
│                                                                    │
│   ~/.wrongstack/projects/<slug>/                                  │
│   ├── _mailbox.sqlite           ← shared message store              │
│   ├── _mailbox.registry.json    ← agent heartbeats                  │
│   └── _mailbox.clients.json     ← REPL/TUI/WebUI/external clients   │
│                                                                    │
│              ▲             ▲             ▲             ▲            │
│              │             │             │             │            │
│       ┌──────┴───┐  ┌──────┴───┐  ┌──────┴───┐  ┌──────┴───┐       │
│       │ Leader A │  │ BugHunter│  │ WebUI    │  │ External │        │
│       │ (CLI)    │  │ (CLI)    │  │ (browser)│  │ agent    │        │
│       └──────────┘  └──────────┘  └──────────┘  └─────▲────┘       │
│                                                       │            │
│                                            HTTP POST │ /mailbox/* │
│                                                       │            │
└───────────────────────────────────────────────────────┼────────────┘
                                                        │
                                          ┌─────────────┴───────────┐
                                          │  wstack mailbox serve   │
                                          │  (this skill)           │
                                          │  wraps GlobalMailbox    │
                                          └─────────────────────────┘

The bridge does NOT introduce a parallel store. External calls go through GlobalMailbox, so agent heartbeats, read receipts, and HQ telemetry happen exactly as they do for WrongStack-internal callers. An external agent and a WrongStack-internal agent posting to the same agentId are indistinguishable to the rest of the system — the WebUI's "online agents" panel will show them side by side, with source = 'http' distinguishing the HTTP path.

When to use this skill

  • The user asks to "let Claude Code send/receive on the mailbox".
  • The user wants to run a script (build bot, CI hook, alerting agent) alongside WrongStack that should participate in the project's inter-agent coordination.
  • The user wants to debug or inspect mailbox traffic from another tool without granting it access to the JSONL file.

When NOT to use this skill

  • The external agent speaks MCP natively — use wstack mcp serve instead (it exposes WrongStack's tool registry, including the mailbox tool).
  • The user wants SMTP/IMAP-style email integration — WrongStack's mailbox is internal-only and is not an email server. Reject that direction.
  • The user wants the external agent to act on the wider file system or other WrongStack tools — the bridge exposes ONLY mailbox operations.

Setup

Run from any terminal where wstack is on PATH and the project is the working directory:

wstack mailbox serve

Or, if the user is already in a WrongStack REPL/TUI:

/mailbox-serve

To have every WrongStack surface start or join the bridge on boot, set features.mailboxBridge: "auto" in the project config. The default is "off", because nothing inside WrongStack needs the bridge — only external agents do.

The server prints its bind URL and writes the bearer token to ~/.wrongstack/projects/<slug>/.mailbox.token (mode 0600). The token is rotated on every server start, so external agents must read it freshly each time they connect — never hardcode.

To pass it to the external agent, set two environment variables:

WRONGSTACK_MAILBOX_URL=http://127.0.0.1:7788
WRONGSTACK_MAILBOX_TOKEN=$(cat ~/.wrongstack/projects/<slug>/.mailbox.token)
Flags
FlagDefaultNotes
--host <ip>127.0.0.1Loopback by default. Pass 0.0.0.0 to expose on LAN — NOT recommended without a reverse proxy that re-authenticates and rate-limits.
--port <n>7788Requested port used when --strict-port is set. In non-strict mode the server deliberately passes port 0 so the OS assigns a free port, even when a port value was supplied.
--strict-portoffBind the requested/default port exactly and fail on EADDRINUSE; without it, bind an OS-assigned free port.

Routes

All routes take JSON bodies on POST (or no body on GET). All requests require Authorization: Bearer <token>. All responses are JSON.

MethodPathWraps
POST/mailbox/sendGlobalMailbox.send
POST/mailbox/queryGlobalMailbox.query
POST/mailbox/checkconvenience inbox check: direct/base/broadcast query plus optional read/completion batch ack
POST/mailbox/ackGlobalMailbox.ack
POST/mailbox/ack-manyGlobalMailbox.ackMany (batch under one lock + rewrite)
POST/mailbox/unread-countGlobalMailbox.unreadCount
POST/mailbox/agents/registerGlobalMailbox.registerAgent (source = 'http')
POST/mailbox/agents/heartbeatGlobalMailbox.heartbeat
POST/mailbox/register-clientGlobalMailbox.registerClient (source = 'http')
POST/mailbox/heartbeatGlobalMailbox.clientHeartbeat
POST/mailbox/purge-clientsGlobalMailbox.purgeClients
GET/mailbox/agentsGlobalMailbox.getAgentStatuses
GET/mailbox/agents/onlineGlobalMailbox.getOnlineAgents
GET/mailbox/eventsauthenticated SSE stream for mailbox events
GET/healthzliveness probe (no auth or rate limit)
Error shape

Every error response follows the WrongStack API convention:

json
{ "error": { "code": "VALIDATION_ERROR", "message": "field \"from\" is required (string)" } }
CodeHTTPWhen
VALIDATION_ERROR400Missing/wrong-type field in request body, body too large, or invalid JSON.
UNAUTHORIZED401Missing or wrong bearer token.
NOT_FOUND404No route for the request method + URL.
RATE_LIMITED429More than 120 authenticated requests in the rolling 60-second window.
INTERNAL_ERROR500GlobalMailbox threw (e.g. store unavailable, disk full).
Limits
  • Body cap: 256 KB. The mailbox message format is small; this leaves headroom for long bodies and base64 attachments while rejecting pathological payloads before they reach JSON.parse.
  • Authenticated routes share a per-bearer sliding-window limit of 120 requests per 60 seconds. /healthz bypasses authentication and the limit. This bounds accidental flooding; it is not an identity or authorization boundary because every caller uses the same project token.

The HQ dashboard writes to the same mailbox

The HQ command center (wstack --hq) shares this exact GlobalMailbox. When an operator sends a prompt from the HQ screen, it lands in the same _mailbox.sqlite store an external agent reads through /mailbox/query — so an external agent participating via this bridge sees HQ prompts too.

HQ delivers a prompt one of two ways:

  • POST /api/command on the HQ server — routes to a connected client, which then calls GlobalMailbox.send.
  • POST /api/mailbox-send on the HQ server — writes to the project mailbox directly, so the prompt is delivered even when no agent is connected. The HQ server resolves the target projectRoot from its SessionRegistry (never a browser-supplied path).

Either way, the resulting mailbox message carries one of the HQ send types, which map onto the mailbox type field an external agent will observe:

HQ send typeMailbox typeIntent for the receiver
steersteerChange course now.
btwbtwFYI / context — no course change demanded.
queuenoteA queued prompt; handle before the next step.
broadcastbroadcastSent to all agents on the project (to: all).

An external agent does not need to distinguish HQ-originated messages — they arrive with from set to hq@<tag> and are read, acked, and completed through the same /mailbox/query + /mailbox/ack routes as any other message. Filter on from if you want to treat HQ prompts specially.

Pairing with the external-facing skill

This internal skill describes how to run the server. The wrongstack-mailbox skill (also bundled with @wrongstack/core) describes how the external agent uses the routes. When configuring an external agent, install both:

  • In the WrongStack project: bundledSkillsDir/mailbox-bridge/ (this file)
  • In the external agent's project: copy bundledSkillsDir/wrongstack-mailbox/SKILL.md to the agent's skills directory (e.g. .claude/skills/wrongstack-mailbox/SKILL.md). The repo ships scripts/install-mailbox-bridge-skills.sh for this.
Show full SKILL.md (687 more words)Show less

Examples

Before using this workflow, read the complete instructions. Load with skill({ name: "mailbox-bridge", resource: "references/examples.md" }), or resolve the reference relative to this skill directory in another client.

How it ends

Ctrl+C (SIGINT) or SIGTERM triggers a graceful shutdown: stop accepting new connections, let in-flight requests finish, flush the mailbox cache, unlink the token file. The mailbox_serve_started and mailbox_serve_stopping JSON log lines on stdout are the deterministic hooks for any log-shipper watching the process.

Health watchdog

packages/core/src/coordination/mailbox-health.ts provides a MailboxHealthWatchdog that probes /healthz and sends a mailbox-bridge-down message to the project mailbox when the bridge stops responding (and a recovery message when it returns). Nothing starts it automatically and no slash command exists for it: host code constructs new MailboxHealthWatchdog({ mailbox, url }) and calls start(). Defaults: probe every 15 s, 3 s timeout, alert after 2 consecutive failures.

Security notes

  • The token is the only credential. Anyone who can read ~/.wrongstack/projects/<slug>/.mailbox.token AND reach the bind host can act on the project's mailbox. Loopback binding makes "reach" require shell access on the host machine.
  • The shared bearer is not bound to an agent identity or capability set. An authenticated caller supplies message from/type, registration ids, and acknowledgement readerId; the bridge does not separately authorize steer/control messages or prevent impersonation. Add an identity-aware trusted proxy before exposing it beyond mutually trusted local clients.
  • Token comparison uses timingSafeEqual.
  • The bridge does NOT log message bodies. The structured mailbox_serve_started event includes the bind URL, port, project dir, and token path — never the token itself.
  • The HTTP server has no request logging at the access-log level. If audit trails of which external agent called which route are needed, the agent itself should log them client-side.

Out of scope

  • Don't expose the bridge on 0.0.0.0 without a trusted reverse proxy. Loopback binding makes "reach" require shell access on the host. LAN exposure without re-authentication and rate-limiting at the proxy is a trust leak.
  • Don't log the bearer token. The structured mailbox_serve_started event includes bind URL, port, project dir, and token path — never the token itself. Logging it once is a permanent compromise.
  • Don't treat the bearer as identity-bound. Every caller uses the same project token. The bridge does not separately authorize steer/control messages or prevent impersonation; the caller can claim any from, type, or readerId. Add an identity-aware trusted proxy before exposing beyond mutually trusted local clients.
  • Don't expose the filesystem, shell, or non-mailbox tools through the bridge. It is the mailbox surface only. If a caller needs more, they need a different bridge.
  • Don't start the bridge for an external agent that already speaks MCP natively. Use wstack mcp serve to expose WrongStack's full tool registry including the mailbox tool. Two bridges for the same purpose is operational debt.
  • Don't start a second bridge for the same project. The per-project lock makes later starts join the running bridge; an extra instance on another port only splits external agents between two endpoints.
  • Don't hardcode a token into prompts or committed code. Read it from .mailbox.token or accept it from the environment; re-read after a 401.
  • Don't send control messages through the bridge. Control is a runtime-only surface; the bridge doesn't expose it, and the only legitimate override is steer via the mailbox_manage route, not through the bridge.

Before returning

  • wstack mailbox serve (or mbWithBootstrap) used; no parallel implementation
  • Bind address is 127.0.0.1 unless behind a reverse proxy that re-authenticates
  • Bearer token read from .mailbox.token or env, not hardcoded
  • Token not present in any log line, event, or error message
  • Body cap of 256 KB enforced; rate limit of 120/min/token enforced
  • /healthz reachable; no auth or rate limit on the health probe
  • Pair with wrongstack-mailbox skill for external-agent usage
  • Graceful shutdown handles SIGINT/SIGTERM, flushes the cache, unlinks the token
  • Mailbox health watchdog wired if running unattended
  • No control messages; steer only via the canonical mailbox_manage route

Skills in scope

  • prompt-engineering — for the external-facing wrongstack-mailbox skill that pairs with this one.
  • node-modern — for AbortSignal.timeout patterns the external agent should use when calling these routes.
  • output-standards — for the <nextsteps> shape in the paired external skill.
  • security-scanner — for confirming the bridge's bearer-token handling matches project security conventions.

© WrongStack, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in packages/core/skills/mailbox-bridge of WrongStack/WrongStack.

  • SKILL.md
  • references/examples.md

Open the folder on GitHubat commit ec76a20

Compare with similar skills

Mailbox Bridge next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mailbox Bridge compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mailbox Bridge this skillWrongStack/WrongStack368—~3.9kAutomated safety check: PassMIT
Mailbox Operations Hubagentscope-ai/QwenPaw35k—~2.6kAutomated safety check: PassApache-2.0
QwenPaw Mailbox Operationsagentscope-ai/QwenPaw35k—~1.3kAutomated safety check: PassApache-2.0
Memory Bridgeruvnet/ruflo74k—~601Automated safety check: NotesMIT
External Linksthedaviddias/Front-End-Checklist74k—~773Automated safety check: PassMIT
Broken External Linksthedaviddias/Front-End-Checklist74k—~401Automated safety check: PassMIT

Similar skills

  • Mailbox Operations Hub

    agentscope-ai/QwenPaw

    Connects, registers, and operates a personal mailbox, reading, searching, sending, and organizing, through a managed mail server for nine domains.

    35k GitHub stars~2.6k tokensUpdated 7 days ago
    Productivity & AutomationAuto-check passed
  • QwenPaw Mailbox Operations

    agentscope-ai/QwenPaw

    Single entry point for email tasks in QwenPaw through qwenpawmail-mcp: read, search, send, reply, organize, and bind or register a personal mailbox.

    35k GitHub stars~1.3k tokensUpdated 7 days ago
    Productivity & AutomationAuto-check passed
  • Memory Bridge

    ruvnet/ruflo

    Bridge Claude Code auto-memory into AgentDB with ONNX embeddings, deduplicate, and enable unified cross-project search

    74k GitHub stars~601 tokensUpdated today
    AI & LLM EngineeringAuto-check: notes
  • External Links

    thedaviddias/Front-End-Checklist

    A skill your agent uses when auditing content pages for citation quality, suggesting authoritative sources to link for factual claims, or reviewing whether a page's external link attributes…

    74k GitHub stars~773 tokensUpdated yesterday
    Research & ScienceAuto-check passed
  • Broken External Links

    thedaviddias/Front-End-Checklist

    A skill your agent uses when auditing metadata, crawlability, structured data, or indexability related to Fix or remove broken external links.

    74k GitHub stars~401 tokensUpdated yesterday
    Marketing & SEOAuto-check passed
  • Odoo Woocommerce Bridge

    sickn33/agentic-awesome-skills

    Sync Odoo with WooCommerce: products, inventory, orders, and customers via WooCommerce REST API and Odoo external API.

    47k GitHub starsUsed in 2 repos~1.3k tokens
    Backend & APIsAuto-check passed

More from WrongStack/WrongStack

All 38 skills in this repo
  • Design Craft

    WrongStack/WrongStack

    Design or substantially improve user-facing interfaces with a product-specific visual direction, content hierarchy, and rendered critique.

    368 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Design Critique

    WrongStack/WrongStack

    A skill your agent uses to audit an interface that already exists and say precisely why it looks generated, templated, or unfinished — a scored rubric across composition, typography, color, states…

    368 GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Multi Agent

    WrongStack/WrongStack

    A skill your agent uses whenever work can be split across multiple AI agents running in parallel, or when orchestrating leader/worker patterns in WrongStack.

    368 GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • Web Platform Baseline

    WrongStack/WrongStack

    Use this skill before asserting that a CSS, HTML or accessibility capability is available, unavailable, or the right tool — it carries dated, refreshable platform facts and refuses to let stale…

    368 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Wrongstack Mailbox

    WrongStack/WrongStack

    A skill your agent uses when the user wants to communicate with WrongStack's shared project mailbox from outside WrongStack — read messages sent by WrongStack agents, send replies, broadcast to all…

    368 GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • API Design

    WrongStack/WrongStack

    A skill your agent uses when designing, implementing, or reviewing an HTTP API — endpoints, request and response shapes, errors, pagination, versioning, and authorization.

    368 GitHub stars~1.3k tokensUpdated today
    Auto-check passed

Questions about Mailbox Bridge

What does Mailbox Bridge do?

A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…. Mailbox Bridge is an agent skill from WrongStack/WrongStack. Use this skill when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox", "let Claude Code read the mailbox", "external agent mailbox", "mailbox bridge", or "HTTP mailbox bridge".

When should I use Mailbox Bridge?

Mailbox Bridge fits situations like: external coding agents (Claude Code; custom scripts) need to participate in the projects shared WrongStack mailbox; A user asks to expose the mailbox; let Claude Code read the mailbox.

How do I install Mailbox Bridge in Claude Code?

Run `npx skills add WrongStack/WrongStack --skill mailbox-bridge -a claude-code`. Or copy the skill folder (packages/core/skills/mailbox-bridge in WrongStack/WrongStack) into .claude/skills/mailbox-bridge in your project. Claude Code loads it when a task matches its description.

How do I install Mailbox Bridge in Codex?

Run `npx skills add WrongStack/WrongStack --skill mailbox-bridge -a codex`. Or copy the skill folder (packages/core/skills/mailbox-bridge in WrongStack/WrongStack) into .agents/skills/mailbox-bridge in your project. Codex loads it when a task matches its description.

Can I use Mailbox Bridge in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add WrongStack/WrongStack --skill mailbox-bridge -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mailbox-bridge, .gemini/skills/mailbox-bridge, .github/skills/mailbox-bridge and .opencode/skills/mailbox-bridge in your project.

What does Mailbox Bridge need to run?

Going by SKILL.md and its folder, Mailbox Bridge needs credentials named WRONGSTACK_MAILBOX_TOKEN. Our summary lists: A credential in WRONGSTACK_MAILBOX_TOKEN.

Does Mailbox Bridge access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Mailbox Bridge safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Mailbox Bridge use?

Mailbox Bridge is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Mailbox Bridge use?

About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 732 tokens, read only when the agent opens those files.

What are the alternatives to Mailbox Bridge?

Skills that share tags, products or a category with Mailbox Bridge: Mailbox Operations Hub (agentscope-ai/QwenPaw, 35k stars), QwenPaw Mailbox Operations (agentscope-ai/QwenPaw, 35k stars), Memory Bridge (ruvnet/ruflo, 74k stars) and External Links (thedaviddias/Front-End-Checklist, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mailbox Bridge?

WrongStack (a GitHub organization) maintains it in WrongStack/WrongStack, which has 368 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on October 6, 2026.

Source: WrongStack/WrongStack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.