Mailbox Operations Hub
agentscope-ai/QwenPaw
Connects, registers, and operates a personal mailbox, reading, searching, sending, and organizing, through a managed mail server for nine domains.
A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…
$ npx skills add WrongStack/WrongStack --skill mailbox-bridge -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install WrongStack/WrongStack mailbox-bridge --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/core/skills/mailbox-bridge .claude/skills/mailbox-bridge && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "mailbox-bridge" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/mailbox-bridge into .claude/skills/mailbox-bridge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mailbox-bridge", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/mailbox-bridgeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add WrongStack/WrongStack --skill mailbox-bridge -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install WrongStack/WrongStack mailbox-bridge --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .agents/skills && cp -r skills-src/packages/core/skills/mailbox-bridge .agents/skills/mailbox-bridge && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "mailbox-bridge" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/mailbox-bridge into .agents/skills/mailbox-bridge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mailbox-bridge", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add WrongStack/WrongStack --skill mailbox-bridge -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install WrongStack/WrongStack mailbox-bridge --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/packages/core/skills/mailbox-bridge .cursor/skills/mailbox-bridge && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "mailbox-bridge" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/mailbox-bridge into .cursor/skills/mailbox-bridge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mailbox-bridge", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/WrongStack/WrongStack.git --path packages/core/skills/mailbox-bridge--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add WrongStack/WrongStack --skill mailbox-bridge -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install WrongStack/WrongStack mailbox-bridge --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/packages/core/skills/mailbox-bridge .gemini/skills/mailbox-bridge && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "mailbox-bridge" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/mailbox-bridge into .gemini/skills/mailbox-bridge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mailbox-bridge", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install WrongStack/WrongStack mailbox-bridgeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add WrongStack/WrongStack --skill mailbox-bridge -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .github/skills && cp -r skills-src/packages/core/skills/mailbox-bridge .github/skills/mailbox-bridge && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "mailbox-bridge" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/mailbox-bridge into .github/skills/mailbox-bridge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mailbox-bridge", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add WrongStack/WrongStack --skill mailbox-bridge -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install WrongStack/WrongStack mailbox-bridge --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/packages/core/skills/mailbox-bridge .opencode/skills/mailbox-bridge && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "mailbox-bridge" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/mailbox-bridge into .opencode/skills/mailbox-bridge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mailbox-bridge", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
mailbox-bridgeA skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…
Mailbox Bridge is an agent skill from WrongStack/WrongStack. Use this skill when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox", "let Claude Code read the mailbox", "external agent mailbox", "mailbox bridge", or "HTTP mailbox bridge". Starts a loopback HTTP façade over the same GlobalMailbox that WrongStack-internal agents already share, so any agent with curl or fetch can read, send, and acknowledge messages.
Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/examples.md`).
The repository describes itself as: An AI coding agent that reads your code, edits files, runs commands, and reasons through bugs — across a terminal REPL, a full-screen TUI, and a browser UI, while you keep your… The licence is MIT.
Read from SKILL.md and the folder at commit ec76a20. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are json).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
WRONGSTACK_MAILBOX_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Mailbox Bridge loads about 3.9k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 122 tokens; SKILL.md has 1,684 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from WrongStack/WrongStack at commit ec76a20, republished under its MIT licence (© WrongStack). 1,684 words, ~3,909 tokens.
.claude/skills/mailbox-bridge/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Bundled skill. This file is shipped with
@wrongstack/coreand auto-discovered viabundledSkillsDir. To pin it to a specific project, runwstack skill install <path-to-this-file>once — the project-level manifest at~/.wrongstack/projects/<slug>/installed-skills.jsonwill record that override.
WrongStack-internal agents (CLI, TUI, WebUI, ACP) already share one
project-level mailbox, a SQLite store at
~/.wrongstack/projects/<slug>/_mailbox.sqlite.
This skill starts a thin loopback HTTP server that wraps that exact same
GlobalMailbox so external coding agents — Claude Code, Aider, Continue,
a user's own scripts — can read and send messages on the same channel
without touching the store directly.
┌────────────────────────────────────────────────────────────────────┐
│ WrongStack project dir │
│ │
│ ~/.wrongstack/projects/<slug>/ │
│ ├── _mailbox.sqlite ← shared message store │
│ ├── _mailbox.registry.json ← agent heartbeats │
│ └── _mailbox.clients.json ← REPL/TUI/WebUI/external clients │
│ │
│ ▲ ▲ ▲ ▲ │
│ │ │ │ │ │
│ ┌──────┴───┐ ┌──────┴───┐ ┌──────┴───┐ ┌──────┴───┐ │
│ │ Leader A │ │ BugHunter│ │ WebUI │ │ External │ │
│ │ (CLI) │ │ (CLI) │ │ (browser)│ │ agent │ │
│ └──────────┘ └──────────┘ └──────────┘ └─────▲────┘ │
│ │ │
│ HTTP POST │ /mailbox/* │
│ │ │
└───────────────────────────────────────────────────────┼────────────┘
│
┌─────────────┴───────────┐
│ wstack mailbox serve │
│ (this skill) │
│ wraps GlobalMailbox │
└─────────────────────────┘The bridge does NOT introduce a parallel store. External calls go through
GlobalMailbox, so agent heartbeats,
read receipts, and HQ telemetry happen exactly as they do for
WrongStack-internal callers. An external agent and a WrongStack-internal
agent posting to the same agentId are indistinguishable to the rest of
the system — the WebUI's "online agents" panel will show them side by
side, with source = 'http' distinguishing the HTTP path.
wstack mcp serve instead
(it exposes WrongStack's tool registry, including the mailbox tool).Run from any terminal where wstack is on PATH and the project is the
working directory:
wstack mailbox serveOr, if the user is already in a WrongStack REPL/TUI:
/mailbox-serveTo have every WrongStack surface start or join the bridge on boot, set
features.mailboxBridge: "auto" in the project config. The default is
"off", because nothing inside WrongStack needs the bridge — only external
agents do.
The server prints its bind URL and writes the bearer token to
~/.wrongstack/projects/<slug>/.mailbox.token (mode 0600). The token
is rotated on every server start, so external agents must read it
freshly each time they connect — never hardcode.
To pass it to the external agent, set two environment variables:
WRONGSTACK_MAILBOX_URL=http://127.0.0.1:7788
WRONGSTACK_MAILBOX_TOKEN=$(cat ~/.wrongstack/projects/<slug>/.mailbox.token)| Flag | Default | Notes |
|---|---|---|
--host <ip> | 127.0.0.1 | Loopback by default. Pass 0.0.0.0 to expose on LAN — NOT recommended without a reverse proxy that re-authenticates and rate-limits. |
--port <n> | 7788 | Requested port used when --strict-port is set. In non-strict mode the server deliberately passes port 0 so the OS assigns a free port, even when a port value was supplied. |
--strict-port | off | Bind the requested/default port exactly and fail on EADDRINUSE; without it, bind an OS-assigned free port. |
All routes take JSON bodies on POST (or no body on GET). All requests
require Authorization: Bearer <token>. All responses are JSON.
| Method | Path | Wraps |
|---|---|---|
| POST | /mailbox/send | GlobalMailbox.send |
| POST | /mailbox/query | GlobalMailbox.query |
| POST | /mailbox/check | convenience inbox check: direct/base/broadcast query plus optional read/completion batch ack |
| POST | /mailbox/ack | GlobalMailbox.ack |
| POST | /mailbox/ack-many | GlobalMailbox.ackMany (batch under one lock + rewrite) |
| POST | /mailbox/unread-count | GlobalMailbox.unreadCount |
| POST | /mailbox/agents/register | GlobalMailbox.registerAgent (source = 'http') |
| POST | /mailbox/agents/heartbeat | GlobalMailbox.heartbeat |
| POST | /mailbox/register-client | GlobalMailbox.registerClient (source = 'http') |
| POST | /mailbox/heartbeat | GlobalMailbox.clientHeartbeat |
| POST | /mailbox/purge-clients | GlobalMailbox.purgeClients |
| GET | /mailbox/agents | GlobalMailbox.getAgentStatuses |
| GET | /mailbox/agents/online | GlobalMailbox.getOnlineAgents |
| GET | /mailbox/events | authenticated SSE stream for mailbox events |
| GET | /healthz | liveness probe (no auth or rate limit) |
Every error response follows the WrongStack API convention:
{ "error": { "code": "VALIDATION_ERROR", "message": "field \"from\" is required (string)" } }| Code | HTTP | When |
|---|---|---|
VALIDATION_ERROR | 400 | Missing/wrong-type field in request body, body too large, or invalid JSON. |
UNAUTHORIZED | 401 | Missing or wrong bearer token. |
NOT_FOUND | 404 | No route for the request method + URL. |
RATE_LIMITED | 429 | More than 120 authenticated requests in the rolling 60-second window. |
INTERNAL_ERROR | 500 | GlobalMailbox threw (e.g. store unavailable, disk full). |
JSON.parse./healthz bypasses authentication and the limit.
This bounds accidental flooding; it is not an identity or authorization
boundary because every caller uses the same project token.The HQ command center (wstack --hq) shares this exact GlobalMailbox.
When an operator sends a prompt from the HQ screen, it lands in the same
_mailbox.sqlite store an external agent reads through /mailbox/query — so an
external agent participating via this bridge sees HQ prompts too.
HQ delivers a prompt one of two ways:
POST /api/command on the HQ server — routes to a connected
client, which then calls GlobalMailbox.send.POST /api/mailbox-send on the HQ server — writes to the project
mailbox directly, so the prompt is delivered even when no agent is
connected. The HQ server resolves the target projectRoot from its
SessionRegistry (never a browser-supplied path).Either way, the resulting mailbox message carries one of the HQ send
types, which map onto the mailbox type field an external agent will
observe:
| HQ send type | Mailbox type | Intent for the receiver |
|---|---|---|
steer | steer | Change course now. |
btw | btw | FYI / context — no course change demanded. |
queue | note | A queued prompt; handle before the next step. |
broadcast | broadcast | Sent to all agents on the project (to: all). |
An external agent does not need to distinguish HQ-originated messages —
they arrive with from set to hq@<tag> and are read, acked, and
completed through the same /mailbox/query + /mailbox/ack routes as
any other message. Filter on from if you want to treat HQ prompts
specially.
This internal skill describes how to run the server. The
wrongstack-mailbox skill (also bundled with @wrongstack/core) describes
how the external agent uses the routes. When configuring an external agent,
install both:
bundledSkillsDir/mailbox-bridge/ (this file)bundledSkillsDir/wrongstack-mailbox/SKILL.md to the agent's skills
directory (e.g. .claude/skills/wrongstack-mailbox/SKILL.md).
The repo ships scripts/install-mailbox-bridge-skills.sh for this.Before using this workflow, read the complete instructions.
Load with skill({ name: "mailbox-bridge", resource: "references/examples.md" }), or resolve the reference relative to this skill directory in another client.
Ctrl+C (SIGINT) or SIGTERM triggers a graceful shutdown: stop accepting
new connections, let in-flight requests finish, flush the mailbox cache,
unlink the token file. The mailbox_serve_started and
mailbox_serve_stopping JSON log lines on stdout are the deterministic
hooks for any log-shipper watching the process.
packages/core/src/coordination/mailbox-health.ts provides a
MailboxHealthWatchdog that probes /healthz and sends a
mailbox-bridge-down message to the project mailbox when the bridge stops
responding (and a recovery message when it returns). Nothing starts it
automatically and no slash command exists for it: host code constructs
new MailboxHealthWatchdog({ mailbox, url }) and calls start(). Defaults:
probe every 15 s, 3 s timeout, alert after 2 consecutive failures.
~/.wrongstack/projects/<slug>/.mailbox.token AND reach the bind host
can act on the project's mailbox. Loopback binding makes "reach"
require shell access on the host machine.from/type, registration ids, and
acknowledgement readerId; the bridge does not separately authorize
steer/control messages or prevent impersonation. Add an identity-aware
trusted proxy before exposing it beyond mutually trusted local clients.timingSafeEqual.mailbox_serve_started event includes the bind URL, port, project dir,
and token path — never the token itself.0.0.0.0 without a trusted reverse proxy. Loopback binding makes "reach" require shell access on the host. LAN exposure without re-authentication and rate-limiting at the proxy is a trust leak.mailbox_serve_started event includes bind URL, port, project dir, and token path — never the token itself. Logging it once is a permanent compromise.steer/control messages or prevent impersonation; the caller can claim any from, type, or readerId. Add an identity-aware trusted proxy before exposing beyond mutually trusted local clients.wstack mcp serve to expose WrongStack's full tool registry including the mailbox tool. Two bridges for the same purpose is operational debt..mailbox.token or accept it from the environment; re-read after a 401.control messages through the bridge. Control is a runtime-only surface; the bridge doesn't expose it, and the only legitimate override is steer via the mailbox_manage route, not through the bridge.wstack mailbox serve (or mbWithBootstrap) used; no parallel implementation127.0.0.1 unless behind a reverse proxy that re-authenticates.mailbox.token or env, not hardcoded/healthz reachable; no auth or rate limit on the health probewrongstack-mailbox skill for external-agent usagecontrol messages; steer only via the canonical mailbox_manage routeprompt-engineering — for the external-facing wrongstack-mailbox
skill that pairs with this one.node-modern — for AbortSignal.timeout patterns the external agent
should use when calling these routes.output-standards — for the <nextsteps> shape in the paired
external skill.security-scanner — for confirming the bridge's bearer-token handling
matches project security conventions.© WrongStack, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in packages/core/skills/mailbox-bridge of WrongStack/WrongStack.
Open the folder on GitHubat commit ec76a20
Mailbox Bridge next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Mailbox Bridge this skillWrongStack/WrongStack | 368 | — | ~3.9k | Automated safety check: Pass | MIT | |
| Mailbox Operations Hubagentscope-ai/QwenPaw | 35k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | |
| QwenPaw Mailbox Operationsagentscope-ai/QwenPaw | 35k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Memory Bridgeruvnet/ruflo | 74k | — | ~601 | Automated safety check: Notes | MIT | |
| External Linksthedaviddias/Front-End-Checklist | 74k | — | ~773 | Automated safety check: Pass | MIT | |
| Broken External Linksthedaviddias/Front-End-Checklist | 74k | — | ~401 | Automated safety check: Pass | MIT |
agentscope-ai/QwenPaw
Connects, registers, and operates a personal mailbox, reading, searching, sending, and organizing, through a managed mail server for nine domains.
agentscope-ai/QwenPaw
Single entry point for email tasks in QwenPaw through qwenpawmail-mcp: read, search, send, reply, organize, and bind or register a personal mailbox.
ruvnet/ruflo
Bridge Claude Code auto-memory into AgentDB with ONNX embeddings, deduplicate, and enable unified cross-project search
thedaviddias/Front-End-Checklist
A skill your agent uses when auditing content pages for citation quality, suggesting authoritative sources to link for factual claims, or reviewing whether a page's external link attributes…
thedaviddias/Front-End-Checklist
A skill your agent uses when auditing metadata, crawlability, structured data, or indexability related to Fix or remove broken external links.
sickn33/agentic-awesome-skills
Sync Odoo with WooCommerce: products, inventory, orders, and customers via WooCommerce REST API and Odoo external API.
WrongStack/WrongStack
Design or substantially improve user-facing interfaces with a product-specific visual direction, content hierarchy, and rendered critique.
WrongStack/WrongStack
A skill your agent uses to audit an interface that already exists and say precisely why it looks generated, templated, or unfinished — a scored rubric across composition, typography, color, states…
WrongStack/WrongStack
A skill your agent uses whenever work can be split across multiple AI agents running in parallel, or when orchestrating leader/worker patterns in WrongStack.
WrongStack/WrongStack
Use this skill before asserting that a CSS, HTML or accessibility capability is available, unavailable, or the right tool — it carries dated, refreshable platform facts and refuses to let stale…
WrongStack/WrongStack
A skill your agent uses when the user wants to communicate with WrongStack's shared project mailbox from outside WrongStack — read messages sent by WrongStack agents, send replies, broadcast to all…
WrongStack/WrongStack
A skill your agent uses when designing, implementing, or reviewing an HTTP API — endpoints, request and response shapes, errors, pagination, versioning, and authorization.
A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…. Mailbox Bridge is an agent skill from WrongStack/WrongStack. Use this skill when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox", "let Claude Code read the mailbox", "external agent mailbox", "mailbox bridge", or "HTTP mailbox bridge".
Mailbox Bridge fits situations like: external coding agents (Claude Code; custom scripts) need to participate in the projects shared WrongStack mailbox; A user asks to expose the mailbox; let Claude Code read the mailbox.
Run `npx skills add WrongStack/WrongStack --skill mailbox-bridge -a claude-code`. Or copy the skill folder (packages/core/skills/mailbox-bridge in WrongStack/WrongStack) into .claude/skills/mailbox-bridge in your project. Claude Code loads it when a task matches its description.
Run `npx skills add WrongStack/WrongStack --skill mailbox-bridge -a codex`. Or copy the skill folder (packages/core/skills/mailbox-bridge in WrongStack/WrongStack) into .agents/skills/mailbox-bridge in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add WrongStack/WrongStack --skill mailbox-bridge -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mailbox-bridge, .gemini/skills/mailbox-bridge, .github/skills/mailbox-bridge and .opencode/skills/mailbox-bridge in your project.
Going by SKILL.md and its folder, Mailbox Bridge needs credentials named WRONGSTACK_MAILBOX_TOKEN. Our summary lists: A credential in WRONGSTACK_MAILBOX_TOKEN.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Mailbox Bridge is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 732 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Mailbox Bridge: Mailbox Operations Hub (agentscope-ai/QwenPaw, 35k stars), QwenPaw Mailbox Operations (agentscope-ai/QwenPaw, 35k stars), Memory Bridge (ruvnet/ruflo, 74k stars) and External Links (thedaviddias/Front-End-Checklist, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
WrongStack (a GitHub organization) maintains it in WrongStack/WrongStack, which has 368 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on October 6, 2026.
Source: WrongStack/WrongStack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.