AgentCloak
Secure email proxy for AI agents. AgentCloak sits between your agent and your email, so the agent gets useful email access without seeing credentials, sensitive financial data, PII, or prompt injection attacks.
Every other email skill on ClawHub gives your agent raw, unfiltered access to your inbox. AgentCloak is the only one with a built-in security pipeline.
What makes this different
- Credential isolation — your email password/OAuth tokens stay server-side; the agent only has an API key
- 4-stage content filter — blocklist, HTML sanitizer, PII redaction, prompt injection detection
- Read + draft only — agents can search, read, list, and draft emails but cannot send, delete, or modify anything
- Draft safety — drafts are never sent automatically; you review them first
- Self-host or hosted — run your own instance or use the hosted version
Setup
Option A: Hosted version (quickest)
- Sign up at https://agentcloak.up.railway.app
- Connect your email (IMAP works with any provider, Gmail OAuth available by invite)
- Create an API key in the dashboard
- Configure:
export AGENTCLOAK_API_KEY=ac_your_key_here
mcporter config add agentcloak \
--baseUrl "https://agentcloak.up.railway.app/mcp" \
--header "Authorization: Bearer $AGENTCLOAK_API_KEY"
Option B: Self-hosted
- Clone and run:
git clone https://github.com/ryanfren/AgentCloak.git
cd agentcloak
pnpm install && pnpm build && pnpm dev
- Open http://localhost:3000, create an account, connect email, create API key
- Configure:
export AGENTCLOAK_URL=http://localhost:3000
export AGENTCLOAK_API_KEY=ac_your_key_here
mcporter config add agentcloak \
--baseUrl "${AGENTCLOAK_URL}/mcp" \
--header "Authorization: Bearer $AGENTCLOAK_API_KEY"
Requirements for self-hosting: Node.js 20+, pnpm 10+
Available tools
| Tool |
Description |
Key parameters |
search_emails |
Search emails with Gmail-style queries |
query, max_results (1-200), page_token |
read_email |
Read full email content by ID |
message_id |
list_threads |
List conversation threads |
query, max_results, page_token |
get_thread |
Read all messages in a thread |
thread_id |
create_draft |
Create a draft (not sent) |
to, subject, body, in_reply_to_thread_id |
list_drafts |
List existing drafts |
max_results |
list_labels |
List all labels with unread counts |
(none) |
get_provider_info |
Get provider type and capabilities |
(none) |
Usage examples
# Search for unread emails
mcporter call agentcloak.search_emails query:"is:unread" max_results:10
# Read a specific email
mcporter call agentcloak.read_email message_id:"abc123"
# Get a full conversation thread
mcporter call agentcloak.get_thread thread_id:"thread456"
# Draft a reply (not sent until you review it)
mcporter call agentcloak.create_draft subject:"Re: Meeting" body:"Sounds good, see you Thursday." in_reply_to_thread_id:"thread456"
# List labels and unread counts
mcporter call agentcloak.list_labels
Security pipeline
Every email passes through a 4-stage filter before the agent sees it. Each stage is independently configurable from the dashboard.
Stage 1: Blocklist
Blocks emails from sensitive senders outright. Three toggleable categories:
- Financial — 40+ domains (Chase, PayPal, Venmo, Coinbase, etc.)
- Security senders — patterns like security@, fraud@, alerts@, .gov addresses
- Security subjects — password resets, 2FA codes, verification links, login alerts
Plus custom blocklists: add your own domains, sender patterns, or subject patterns.
Stage 2: HTML sanitizer
Converts HTML email to plaintext and strips dangerous Unicode (zero-width characters, bidirectional overrides, tag characters, variation selectors) that could be used to hide prompt injection.
Stage 3: PII redaction
Redacts sensitive patterns with placeholders:
- SSNs, credit card numbers, bank account/routing numbers
- API keys (
sk_, pk_, AWS keys), bearer tokens, PEM private keys
- Optionally: email addresses, large dollar amounts
Stage 4: Prompt injection detection
Scans for 19 known injection patterns (instruction overrides, role reassignments, system tag injections, data exfiltration attempts). Flags detected content with a [AGENTCLOAK WARNING] prefix so the agent knows the email may be adversarial. Does not block — lets the agent make an informed decision.
Security and privacy
What data leaves your machine:
| Scenario |
Data flow |
| Self-hosted |
Nothing leaves your machine. All processing is local. |
| Hosted version |
Your email credentials are stored server-side (encrypted). Email content passes through the hosted server's filter pipeline. No data is shared with third parties. |
- API keys are hashed (SHA-256) before storage — the server cannot recover your key after creation
- Email credentials are stored server-side; the agent never sees them
- All filtering happens server-side before content reaches the agent
- The agent can only read and draft — it cannot send, delete, or modify emails
- Source code is open: https://github.com/ryanfren/AgentCloak
Trust statement: By using the hosted version, you trust the AgentCloak server with access to your email account credentials and content. If this is not acceptable, self-host your own instance for full control.
Email providers
AgentCloak supports three connection methods:
- IMAP — works with any email provider (Gmail, Outlook, ProtonMail Bridge, Fastmail, etc.)
- Gmail OAuth — direct API access (currently invite-only during beta)
- Gmail Apps Script — manual setup via script.google.com, no Google Cloud project needed
Limitations
- Read and draft only — no send, delete, or modify
- Gmail search syntax only (even for IMAP connections, queries are translated)
- Attachment content is not accessible (metadata can optionally be shown)
- Gmail OAuth is invite-only during beta; IMAP and Apps Script are open to all
- Hosted version is in beta
Links
1---2name: agentcloak3description: Secure email proxy for AI agents. Search, read, and draft emails via MCP with server-side credential isolation, PII redaction, prompt injection detection, and content filtering. Unlike raw Gmail/IMAP skills, your agent never sees passwords or unfiltered content. Self-host or use the hosted version.4---5
6# AgentCloak
7
8Secure email proxy for AI agents. AgentCloak sits between your agent and your email, so the agent gets useful email access without seeing credentials, sensitive financial data, PII, or prompt injection attacks.
9
10Every other email skill on ClawHub gives your agent raw, unfiltered access to your inbox. AgentCloak is the only one with a built-in security pipeline.
11
12## What makes this different
13
14- **Credential isolation** — your email password/OAuth tokens stay server-side; the agent only has an API key
15- **4-stage content filter** — blocklist, HTML sanitizer, PII redaction, prompt injection detection
16- **Read + draft only** — agents can search, read, list, and draft emails but cannot send, delete, or modify anything
17- **Draft safety** — drafts are never sent automatically; you review them first
18- **Self-host or hosted** — run your own instance or use the hosted version
19
20## Setup
21
22### Option A: Hosted version (quickest)
23
241. Sign up at https://agentcloak.up.railway.app
252. Connect your email (IMAP works with any provider, Gmail OAuth available by invite)
263. Create an API key in the dashboard
274. Configure:
28
29```bash
30export AGENTCLOAK_API_KEY=ac_your_key_here
31mcporter config add agentcloak \
32 --baseUrl "https://agentcloak.up.railway.app/mcp" \
33 --header "Authorization: Bearer $AGENTCLOAK_API_KEY"
34```
35
36### Option B: Self-hosted
37
381. Clone and run:
39
40```bash
41git clone https://github.com/ryanfren/AgentCloak.git
42cd agentcloak
43pnpm install && pnpm build && pnpm dev
44```
45
462. Open http://localhost:3000, create an account, connect email, create API key
473. Configure:
48
49```bash
50export AGENTCLOAK_URL=http://localhost:3000
51export AGENTCLOAK_API_KEY=ac_your_key_here
52mcporter config add agentcloak \
53 --baseUrl "${AGENTCLOAK_URL}/mcp" \
54 --header "Authorization: Bearer $AGENTCLOAK_API_KEY"
55```
56
57**Requirements for self-hosting:** Node.js 20+, pnpm 10+
58
59## Available tools
60
61| Tool | Description | Key parameters |
62|------|-------------|----------------|
63| `search_emails` | Search emails with Gmail-style queries | `query`, `max_results` (1-200), `page_token` |
64| `read_email` | Read full email content by ID | `message_id` |
65| `list_threads` | List conversation threads | `query`, `max_results`, `page_token` |
66| `get_thread` | Read all messages in a thread | `thread_id` |
67| `create_draft` | Create a draft (not sent) | `to`, `subject`, `body`, `in_reply_to_thread_id` |
68| `list_drafts` | List existing drafts | `max_results` |
69| `list_labels` | List all labels with unread counts | (none) |
70| `get_provider_info` | Get provider type and capabilities | (none) |
71
72## Usage examples
73
74```bash
75# Search for unread emails
76mcporter call agentcloak.search_emails query:"is:unread" max_results:10
77
78# Read a specific email
79mcporter call agentcloak.read_email message_id:"abc123"
80
81# Get a full conversation thread
82mcporter call agentcloak.get_thread thread_id:"thread456"
83
84# Draft a reply (not sent until you review it)
85mcporter call agentcloak.create_draft subject:"Re: Meeting" body:"Sounds good, see you Thursday." in_reply_to_thread_id:"thread456"
86
87# List labels and unread counts
88mcporter call agentcloak.list_labels
89```
90
91## Security pipeline
92
93Every email passes through a 4-stage filter before the agent sees it. Each stage is independently configurable from the dashboard.
94
95### Stage 1: Blocklist
96
97Blocks emails from sensitive senders outright. Three toggleable categories:
98
99- **Financial** — 40+ domains (Chase, PayPal, Venmo, Coinbase, etc.)
100- **Security senders** — patterns like security@, fraud@, alerts@, .gov addresses
101- **Security subjects** — password resets, 2FA codes, verification links, login alerts
102
103Plus custom blocklists: add your own domains, sender patterns, or subject patterns.
104
105### Stage 2: HTML sanitizer
106
107Converts HTML email to plaintext and strips dangerous Unicode (zero-width characters, bidirectional overrides, tag characters, variation selectors) that could be used to hide prompt injection.
108
109### Stage 3: PII redaction
110
111Redacts sensitive patterns with placeholders:
112
113- SSNs, credit card numbers, bank account/routing numbers
114- API keys (`sk_`, `pk_`, AWS keys), bearer tokens, PEM private keys
115- Optionally: email addresses, large dollar amounts
116
117### Stage 4: Prompt injection detection
118
119Scans for 19 known injection patterns (instruction overrides, role reassignments, system tag injections, data exfiltration attempts). Flags detected content with a `[AGENTCLOAK WARNING]` prefix so the agent knows the email may be adversarial. Does not block — lets the agent make an informed decision.
120
121## Security and privacy
122
123**What data leaves your machine:**
124
125| Scenario | Data flow |
126|----------|-----------|
127| Self-hosted | Nothing leaves your machine. All processing is local. |
128| Hosted version | Your email credentials are stored server-side (encrypted). Email content passes through the hosted server's filter pipeline. No data is shared with third parties. |
129
130- API keys are hashed (SHA-256) before storage — the server cannot recover your key after creation
131- Email credentials are stored server-side; the agent never sees them
132- All filtering happens server-side before content reaches the agent
133- The agent can only read and draft — it cannot send, delete, or modify emails
134- Source code is open: https://github.com/ryanfren/AgentCloak
135
136**Trust statement:** By using the hosted version, you trust the AgentCloak server with access to your email account credentials and content. If this is not acceptable, self-host your own instance for full control.
137
138## Email providers
139
140AgentCloak supports three connection methods:
141
142- **IMAP** — works with any email provider (Gmail, Outlook, ProtonMail Bridge, Fastmail, etc.)
143- **Gmail OAuth** — direct API access (currently invite-only during beta)
144- **Gmail Apps Script** — manual setup via script.google.com, no Google Cloud project needed
145
146## Limitations
147
148- Read and draft only — no send, delete, or modify
149- Gmail search syntax only (even for IMAP connections, queries are translated)
150- Attachment content is not accessible (metadata can optionally be shown)
151- Gmail OAuth is invite-only during beta; IMAP and Apps Script are open to all
152- Hosted version is in beta
153
154## Links
155
156- Homepage: https://agentcloak.up.railway.app
157- Source: https://github.com/ryanfren/AgentCloak
158- License: BSL 1.1