Agent skill

Wrongstack Mailbox MCP

by WrongStack in WrongStack/WrongStack

Coordinate with WrongStack agents through the project-scoped Mailbox MCP server.

MITAuto-check passedAgent Workflows

Install Wrongstack Mailbox MCP

skills CLI
$ npx skills add WrongStack/WrongStack --skill wrongstack-mailbox-mcp -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install WrongStack/WrongStack wrongstack-mailbox-mcp --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/core/skills/wrongstack-mailbox-mcp .claude/skills/wrongstack-mailbox-mcp && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
wrongstack-mailbox-mcp
GitHub stars
368
Token cost
~1.5k tokens
SKILL.md length
648 words
Files
2
Skills in repo
38
Repo updated
First seen
Licence
MIT

At a glance

Coordinate with WrongStack agents through the project-scoped Mailbox MCP server.

  • Works in 7 steps: Call mcp_use for the remote… → Call mcp_use for the remote mailbox_read… → Call mcp_use for remote mailbox_read… → …
  • An external coding agent needs to inspect unread
  • SKILL.md covers Connect, Coordinate, Observe changes and Manage and administer, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Wrongstack Mailbox MCP is an agent skill from WrongStack/WrongStack. Coordinate with WrongStack agents through the project-scoped Mailbox MCP server. Use when an external coding agent needs to inspect unread or incomplete messages, query conversation history, discover online agents, send direct/reply/broadcast/steer messages, acknowledge outcomes, maintain its presence, soft-delete or restore messages, watch for changes, or perform explicitly authorized Mailbox administration without reading Mailbox files or SQLite directly.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Agent Workflows, covering MCP servers. It works with Model Context Protocol and SQLite. The repository describes itself as: An AI coding agent that reads your code, edits files, runs commands, and reasons through bugs — across a terminal REPL, a full-screen TUI, and a browser UI, while you keep your… The licence is MIT.

When your agent uses it

  • An external coding agent needs to inspect unread
  • Incomplete messages
  • Query conversation history
  • Discover online agents

Example prompts

  • “/wrongstack-mailbox-mcp”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Call mcp_use for the remote mailbox_manage operation with register_self. Include a stable name and role when known.
  2. Call mcp_use for the remote mailbox_read operation with unread, then query. Prefer unreadBy plus incompleteOnly when
  3. Call mcp_use for remote mailbox_read with online_agents before routing a time-sensitive direct message.
  4. Call mcp_use for remote mailbox_manage with send. Set an explicit recipient and message type
  5. Set replyTo when continuing a thread. Do not create an unrelated message that loses context.
  6. Call mcp_use for the remote ack or ack_many operation after reading or completing messages. Record a truthful outcome when
  7. Send heartbeat_self during long work and deregister_self on a clean shutdown.

What it can do on your machine

Read from SKILL.md and the folder at commit ec76a20. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Wrongstack Mailbox MCP loads about 1.5k tokens when it runs. Until then it costs about 121 tokens; SKILL.md has 648 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~121
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from WrongStack/WrongStack at commit ec76a20, republished under its MIT licence (© WrongStack). 648 words, ~1,465 tokens.

Download SKILL.mdSave it as .claude/skills/wrongstack-mailbox-mcp/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
wrongstack-mailbox-mcp
description
Coordinate with WrongStack agents through the project-scoped Mailbox MCP server. Use when an external coding agent needs to inspect unread or incomplete messages, query conversation history, discover online agents, send direct/reply/broadcast/steer messages, acknowledge outcomes, maintain its presence, soft-delete or restore messages, watch for changes, or perform explicitly authorized Mailbox administration without reading Mailbox files or SQLite directly.
audience
external
version
1.0.0
required-capabilities
mcp.dynamic
required-tools
mcp_use

WrongStack Mailbox MCP

Use MCP as the only Mailbox boundary. Never open or edit _mailbox.sqlite, legacy JSONL, credential files, bridge locks, or token files directly.

Connect

Expect an MCP server named wrongstack-mailbox. For full authorized access configure:

json
{
  "mcpServers": {
    "wrongstack-mailbox": {
      "command": "wstack-mailbox-mcp",
      "args": [
        "--project-root",
        "/absolute/project/path",
        "--actor",
        "external-agent",
        "--admin"
      ]
    }
  }
}

Use a stable, honest actor id. The server fixes sender, receipt, deletion, registration, and heartbeat identity to --actor; tool arguments cannot impersonate another actor.

Coordinate

  1. Call mcp_use for the remote mailbox_manage operation with register_self. Include a stable name and role when known.
  2. Call mcp_use for the remote mailbox_read operation with unread, then query. Prefer unreadBy plus incompleteOnly when looking for actionable work.
  3. Call mcp_use for remote mailbox_read with online_agents before routing a time-sensitive direct message.
  4. Call mcp_use for remote mailbox_manage with send. Set an explicit recipient and message type:
    • ask for a blocking question;
    • assign for delegated work;
    • steer for changed direction;
    • review for review requests;
    • result for a completed outcome;
    • broadcast only when every relevant agent should receive it.
  5. Set replyTo when continuing a thread. Do not create an unrelated message that loses context.
  6. Call mcp_use for the remote ack or ack_many operation after reading or completing messages. Record a truthful outcome when marking work completed.
  7. Send heartbeat_self during long work and deregister_self on a clean shutdown.

Runtime-only control messages are deliberately unavailable. Call mcp_use for the remote steer operation for normal external direction; never bypass the restriction through another channel.

Observe changes

Call mcp_use for remote mailbox_watch with an optional event type and timeout no greater than 25 seconds. Treat the result as a wake-up hint. After every event or timeout, reconcile through remote mailbox_read; watch events contain identifiers and metadata, not the authoritative message snapshot.

Manage and administer

  • mailbox_read provides query, unread counts, agent/client discovery, and daemon status.
  • mailbox_manage provides send, receipt/completion acknowledgement, soft-delete/restore, and self-presence. It requires --writable or --admin.
  • mailbox_admin provides clear, purge, compaction, and credential issue/verify/revoke/rotate/list operations. It requires --admin, which implies writable mode.
Show full SKILL.md (324 more words)Show less

Out of scope

  • Don't read or edit Mailbox files directly. No _mailbox.sqlite, no legacy JSONL, no bridge locks, no token files. MCP is the only boundary; bypassing it through any of those channels breaks trust and audit.
  • Don't impersonate another actor. The server fixes sender, receipt, deletion, registration, and heartbeat identity to --actor. Tool arguments cannot override that. Use the actor id you were given, honestly.
  • Don't reach for steer on routine direction. Steer is for changed direction mid-task. For normal coordination, ask, assign, or result are the right types.
  • Don't broadcast when direct addressing is correct. Broadcast reaches every relevant agent; most messages don't.
  • Don't run admin operations to bypass routing, identity, or authorization errors. If a call is denied for one of those reasons, the call is wrong. Re-read state, ask, or stop. Admin paths are for explicitly authorized administration, not workarounds.
  • Don't skip register_self. Without registration, the runtime can't reconcile heartbeats or surface the agent in the workbench.
  • Don't treat mailbox_watch events as authoritative. Watch is a wake-up hint, not a snapshot. After every event, reconcile through mailbox_read.

Before returning

  • MCP server reached via mcp_use; never opened Mailbox files directly
  • Actor id stable and honest; no impersonation of hq@... or other agents
  • register_self called with stable name and role before any other traffic
  • mailbox_read with unreadBy + incompleteOnly used to find actionable work
  • online_agents checked before time-sensitive direct sends
  • send carries an explicit recipient and the right message type
  • replyTo set on threaded replies; no orphan context
  • ack / ack_many called with truthful outcome after work
  • heartbeat_self running during long work; deregister_self on clean shutdown
  • Admin operations (clear_all, purge, credential issue/revoke) only when explicitly requested

Skills in scope

  • mailbox-bridge — for the WrongStack-internal HTTP façade this MCP server mirrors
  • wrongstack-mailbox — for the external-facing counterpart used by Claude Code / Aider / scripts
  • security-scanner — for confirming the MCP server's authn/authz surface matches project security conventions
  • output-standards — for the <nextsteps> shape when reporting mailbox activity to the user

© WrongStack, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in packages/core/skills/wrongstack-mailbox-mcp of WrongStack/WrongStack.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit ec76a20

Compare with similar skills

Wrongstack Mailbox MCP next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Wrongstack Mailbox MCP compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Wrongstack Mailbox MCP this skillWrongStack/WrongStack368—~1.5kAutomated safety check: PassMIT
Memmesh CLIThinkfleetAI/memmesh419—~855Automated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
Foremergenaw103/foremerge536—~2.4kAutomated safety check: PassApache-2.0
Puppetmaster Agent Orchestrationprofessorpalmer/Puppetmaster467—~3.2kAutomated safety check: PassMIT
Clawmemyoloshii/ClawMem210—~7.5kAutomated safety check: PassMIT

Similar skills

  • Memmesh CLI

    ThinkfleetAI/memmesh

    MemMesh CLI + local MCP server — the zero-infra, no-API-key path to the same engine as the hosted SDK.

    419 GitHub stars~855 tokensUpdated 1 mo ago
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • Foremerge

    naw103/foremerge

    Coordinate parallel coding agents with Foremerge's local Git-compatible CLI and MCP server.

    536 GitHub stars~2.4k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Puppetmaster Agent Orchestration

    professorpalmer/Puppetmaster

    Operates and supervises Puppetmaster, a multi-agent orchestrator, through its MCP tools or CLI, picking the right verb for edits, reviews, audits and long-running jobs.

    467 GitHub stars~3.2k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Clawmem

    yoloshii/ClawMem

    ClawMem operational reference for agents at query time — the 3-rule escalation gate, MCP tool routing, the 4 query-optimization levers, pipeline behavior (query vs intentsearch), composite scoring…

    210 GitHub stars~7.5k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Memora

    agentic-box/memora

    A skill your agent uses when working with persistent memory across sessions, storing/retrieving knowledge, managing TODOs/issues, or when context from previous sessions would be helpful.

    731 GitHub stars~813 tokensUpdated 9 days ago
    Agent WorkflowsAuto-check passed

More from WrongStack/WrongStack

All 38 skills in this repo
  • Design Craft

    WrongStack/WrongStack

    Design or substantially improve user-facing interfaces with a product-specific visual direction, content hierarchy, and rendered critique.

    368 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Design Critique

    WrongStack/WrongStack

    A skill your agent uses to audit an interface that already exists and say precisely why it looks generated, templated, or unfinished — a scored rubric across composition, typography, color, states…

    368 GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Mailbox Bridge

    WrongStack/WrongStack

    A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…

    368 GitHub stars~3.9k tokensUpdated today
    Auto-check passed
  • Multi Agent

    WrongStack/WrongStack

    A skill your agent uses whenever work can be split across multiple AI agents running in parallel, or when orchestrating leader/worker patterns in WrongStack.

    368 GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • Web Platform Baseline

    WrongStack/WrongStack

    Use this skill before asserting that a CSS, HTML or accessibility capability is available, unavailable, or the right tool — it carries dated, refreshable platform facts and refuses to let stale…

    368 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Wrongstack Mailbox

    WrongStack/WrongStack

    A skill your agent uses when the user wants to communicate with WrongStack's shared project mailbox from outside WrongStack — read messages sent by WrongStack agents, send replies, broadcast to all…

    368 GitHub stars~3.5k tokensUpdated today
    Auto-check passed

Questions about Wrongstack Mailbox MCP

What does Wrongstack Mailbox MCP do?

Coordinate with WrongStack agents through the project-scoped Mailbox MCP server. Wrongstack Mailbox MCP is an agent skill from WrongStack/WrongStack. Coordinate with WrongStack agents through the project-scoped Mailbox MCP server.

When should I use Wrongstack Mailbox MCP?

Wrongstack Mailbox MCP fits situations like: an external coding agent needs to inspect unread; incomplete messages; query conversation history; discover online agents.

How do I install Wrongstack Mailbox MCP in Claude Code?

Run `npx skills add WrongStack/WrongStack --skill wrongstack-mailbox-mcp -a claude-code`. Or copy the skill folder (packages/core/skills/wrongstack-mailbox-mcp in WrongStack/WrongStack) into .claude/skills/wrongstack-mailbox-mcp in your project. Claude Code loads it when a task matches its description.

How do I install Wrongstack Mailbox MCP in Codex?

Run `npx skills add WrongStack/WrongStack --skill wrongstack-mailbox-mcp -a codex`. Or copy the skill folder (packages/core/skills/wrongstack-mailbox-mcp in WrongStack/WrongStack) into .agents/skills/wrongstack-mailbox-mcp in your project. Codex loads it when a task matches its description.

Can I use Wrongstack Mailbox MCP in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add WrongStack/WrongStack --skill wrongstack-mailbox-mcp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wrongstack-mailbox-mcp, .gemini/skills/wrongstack-mailbox-mcp, .github/skills/wrongstack-mailbox-mcp and .opencode/skills/wrongstack-mailbox-mcp in your project.

What does Wrongstack Mailbox MCP need to run?

SKILL.md names no scripts, command-line tools or credentials: Wrongstack Mailbox MCP is instructions for the agent only.

Does Wrongstack Mailbox MCP access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Wrongstack Mailbox MCP safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Wrongstack Mailbox MCP use?

Wrongstack Mailbox MCP is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Wrongstack Mailbox MCP use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Wrongstack Mailbox MCP?

Skills that share tags, products or a category with Wrongstack Mailbox MCP: Memmesh CLI (ThinkfleetAI/memmesh, 419 stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), Foremerge (naw103/foremerge, 536 stars) and Puppetmaster Agent Orchestration (professorpalmer/Puppetmaster, 467 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Wrongstack Mailbox MCP?

WrongStack (a GitHub organization) maintains it in WrongStack/WrongStack, which has 368 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on October 6, 2026.

Source: WrongStack/WrongStack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.