AgentBox

AgentBox

Sovereign autonomous mailbox and identity layer for AI agents, providing persistent email identities, object-level security, OTP/2FA capture, link safety analysis, and event-driven email handling via MCP.

Category
访问服务器

README

<div align="center">

⚡ AgentBox

The Email & Identity Layer for AI Agents

CI npm version npm downloads GitHub Release Rust MCP License: MIT

<br/>

AgentBox gives any autonomous AI agent (Claude Code, Cursor, Antigravity, OpenAI Swarm) its own machine-native email identity, inbox, outbound communication, authentication, and event-driven email capabilities — self-hosted, sovereign, and blazingly fast.

<br/>

Quick Start • Core Abstraction • Agent Identity & Security • Use Cases • Benchmarks • MCP Tools • Architecture


</div>

<br/>

💡 The Core Problem

Autonomous AI agents need a way to interact with the human world and each other. Today, email is the universal communication protocol across all software and platforms:

  • How does a browser agent verify its account on GitHub or AWS? Email.
  • How does a customer contact your AI support assistant? Email.
  • How does an external QA agent delegate a bug report to a coding agent? Email.
  • How does a research agent receive arXiv digests and industry alerts? Email.

Without machine-native email infrastructure, developers are forced to use brittle API polling, hack personal Gmail inboxes, or manually click verification links.

AgentBox solves this entirely.

                    ┌─────────────────────────┐
                    │        AGENTBOX         │
                    └────────────┬────────────┘
                                 │
              ┌──────────────────┴──────────────────┐
              ▼                                     ▼
        🧑🚀 IDENTITY                         📬 COMMUNICATION
  • User-Defined Name & Email           • Inbound Inbox (SMTP/IMAP/HTTP)
  • Persistent Agent ID                 • Outbound SMTP Relay
  • Scoped Capability Matrix            • Realtime Event Bus (<0.001ms)
  • Object-Level Ownership              • OTP Isolator & SafeLink Engine
              │                                     │
              └──────────────────┬──────────────────┘
                                 │
                                 ▼
                     Autonomous AI Agent

<br/>


🧑‍🚀 Agent Identity & Security Model

AgentBox does not prescribe who your agent is. You define the agent's name, email, and capability policy:

# 1. Create a Support Agent with a custom company email
npx agentbox-mail agent create support \
  --email support@mycompany.com \
  --capabilities "inbox.read,email.send"

# 2. Create an Autonomous Coding Agent
npx agentbox-mail agent create coder \
  --email coder@mycompany.com \
  --capabilities "inbox.read,task.claim,task.update,otp.read"

# 3. Create a Browser QA Agent with standard verification permissions
npx agentbox-mail agent create browser-qa \
  --capabilities "inbox.read,otp.read,links.read"
╔══════════════════════════════════════════════════════════════════╗
║             🧑‍🚀 AGENT IDENTITY PROVISIONED                      ║
╠══════════════════════════════════════════════════════════════════╣
║  Agent ID     : agent_coder_7f92a1                               ║
║  Name         : coder                                            ║
║  Email        : coder@mycompany.com                              ║
║  Auth Token   : agb_92d7e8f1c3a04b12                             ║
║  Capabilities : ["inbox.read", "task.claim", "otp.read"]        ║
║  Status       : active                                           ║
╚══════════════════════════════════════════════════════════════════╝
⚠️  NOTE: Store this auth_token securely. It is only displayed once upon creation.

🔐 Multi-Tier Security Enforcement:

  1. Token Authentication: Verifies agent identity and status (active vs revoked).
  2. Capability Scopes: Validates required permissions (inbox.read, email.send, otp.read, task.claim).
  3. Object-Level Mailbox Ownership: Agent A possessing otp.read is strictly restricted to its own assigned mailboxes (owner_agent_id). Attempting cross-agent access returns an explicit AccessDenied error.
  4. Credential Hygiene: Public queries (get_agent_identity, list_agent_identities) use sanitized structs that never expose tokens.

<br/>


🌐 Versatile Use Cases

AgentBox provides the foundational email identity layer. Here are some of the most powerful workflows built on top of it:

1. 🤖 Agent-to-Agent Work Delegation & Task Protocols

An external QA or discovery agent (like Jules) sends an email with a bug or feature request. AgentBox's built-in TaskDetector automatically parses the subject ([TASK:BUG]), extracts the repository, branch, priority, and line citations, provisions an AgentTask, and wakes the Coding Agent via the event bus:

   Jules (QA Agent)
          │
          │ 1. Sends email: "[TASK:BUG] Fix duplicate property filter in EstateFlow"
          │    Body: "Repository: RABNEER/EstateFlow\nPriority: high\nEvidence: tests/search.spec.ts:87"
          ▼
 ┌─────────────────┐
 │    AgentBox     │ ──► Auto-detects Work Order via `TaskDetector`
 └────────┬────────┘ ──► Provisions `AgentTask` & records audit event
          │
          │ 2. Realtime Event Bus Dispatch (<0.001ms) / SSE Daemon Bridge
          ▼
 Coder (Worker Agent / Claude Code)
          │ 3. Instantaneously claims task via `claim_agent_task`
          │ 4. Fixes code, opens GitHub PR, calls `update_task_progress`
          │ 5. Calls `complete_agent_task` with CI results
          ▼
 ┌─────────────────┐
 │    AgentBox     │ ──► Status: "completed" + Immutable Audit Lineage
 └────────┬────────┘
          │ 6. Emits completion notification to Jules / User
          ▼
   Jules closes ticket

2. 🔐 Autonomous SaaS Signups & 2FA / OTP Verification

Browser agents (Puppeteer, Playwright, Stagehand) need to sign up for tools, verify email addresses, and solve OTP challenges:

  • Agent creates inbox create_agent_inbox(name: "signup-bot").
  • Triggers signup on platform (e.g. AWS, Stripe, Vercel).
  • Calls get_latest_otp() (extracted via regex in <0.14ms) or get_verification_link() (checked with Anti-Redirect & Phishing Defense).
  • Account is verified autonomously with zero human intervention.

3. 💬 Autonomous Inbound Support & Customer Triage

Give your customer support agent its own email address (support@yourcompany.com):

  • Customer emails support with an issue.
  • AgentBox ingests the email via raw SMTP or IMAP sync.
  • Realtime SSE event notifies the support agent.
  • Agent analyzes the inquiry, consults internal docs, and replies via send_agent_email().

4. 🔬 Research & Intelligence Gathering

Give your research agent an identity (researcher@yourcompany.com):

  • Subscribes to industry newsletters, security advisories (CVEs), and arXiv digest feeds.
  • Agent reads inbound emails periodically using read_agent_inbox().
  • Synthesizes executive briefings, summarizes findings, and forwards digests to your team.

5. 🛡️ DevOps Alerting & Automated Incident Response

Give your incident response agent an identity (oncall@yourcompany.com):

  • Receives critical error alerts from Datadog, Sentry, or PagerDuty.
  • Realtime event hook wakes the agent immediately.
  • Agent queries logs, identifies the failing commit, and dispatches a fix order to the coding agent.

<br/>


📊 Reproducible Performance Benchmarks

AgentBox includes a complete benchmark test suite (tests/benchmark.rs) measuring the entire pipeline from raw bytes to full JSON-RPC output:

cargo test --release --test benchmark -- --nocapture

⚡ Verified Full End-to-End MCP Pipeline (1,000 Cycles):

Tested Pipeline: Raw MIME Ingestion ➔ mail-parser ➔ SafeLink Analysis ➔ Regex OTP ➔ SQLite INSERT ➔ Broadcast Dispatch ➔ Authenticated MCP Tool Call (tools/call) ➔ JSON-RPC Result Output

Pipeline Metric Measured Latency Throughput
Average (Mean) 451.9 µs (0.451 ms) 2,213 complete MCP cycles/sec
p50 Median 431.5 µs (0.431 ms) —
p95 586.2 µs (0.586 ms) —
p99 1.04 ms —

⚡ Sub-Component Microsecond Latencies (10,000 Iterations):

  • Event Bus Channel Dispatch: 0.216 µs (0.0002 ms) — 4.62 Million events/sec
  • Link Safety & Anti-Redirect: 0.652 µs (0.0007 ms) — 1.53 Million checks/sec
  • OTP Regex Extraction: 138.2 µs (0.138 ms) — 7,230 extractions/sec

<br/>


🛠️ MCP Tools Reference

AgentBox implements the Model Context Protocol (MCP) specification over stdio:

Category Tool Parameters Description
Identity create_agent_identity name, email?, capabilities? Creates a persistent identity with custom/auto email and returns a one-time auth token.
Identity get_agent_identity agent_id Retrieves public agent metadata (tokens are sanitized).
Identity list_agent_identities — Lists all registered public agent identities and active policies.
Identity revoke_agent_identity agent_id Revokes an agent identity and invalidates its auth token immediately.
Mailbox create_agent_inbox name, address?, agent_token? Creates a new virtual mailbox linked to the calling agent identity.
Mailbox get_latest_otp account_id, agent_token? Extracts the newest 4–8 digit verification code in <0.14ms with ownership check.
Mailbox wait_for_email account_id, timeout_secs?, agent_token? Event-Driven Hook: Async Tokio broadcast channel wakes the agent in <0.001ms.
Mailbox get_verification_link account_id, agent_token? Returns parsed activation links with Deep Link Safety & Anti-Redirect Defense.
Mailbox read_agent_inbox account_id, limit?, agent_token? Retrieves recent messages, full body text, HTML, and sender metadata.
Mailbox send_agent_email account_id, to, subject, body, agent_token? Dispatches outbound emails via SMTP relay with capability authorization.
Mailbox delete_agent_inbox account_id, agent_token? Deletes a temporary mailbox and purges stored messages.
Task Protocol dispatch_agent_task action, description, repository?, branch?, priority?, target_agent?, evidence?, acceptance_criteria?, agent_token? Dispatches a structured work order from one agent to another.
Task Protocol claim_agent_task task_id, agent_token Atomically locks and assigns a task to the claiming worker agent.
Task Protocol update_task_progress task_id, status, commit_sha?, pr_url?, test_results?, note?, agent_token Updates task status (running, testing, pr_opened) and records audit log.
Task Protocol complete_agent_task task_id, summary, commit_sha?, pr_url?, test_results?, agent_token Closes a task with completion details and emits completion event.
Task Protocol list_agent_tasks status?, agent_token?, limit? Lists tasks filtered by lifecycle state or agent identity.
Task Protocol get_task_audit_trail task_id, agent_token? Retrieves the immutable audit log and lifecycle history for a task.

<br/>


🚀 Quick Start

1. Headless NPM CLI (Zero Setup)

Instantly auto-configure your AI tools in 1 second:

# 1-Click Auto-Install MCP Server & AI Skill into Claude Code, Cursor, Antigravity
npx agentbox-mail init

# Start MCP stdio server with live daemon SSE event bridge
npx agentbox-mail mcp

# Create an Agent Identity with scoped capabilities
npx agentbox-mail agent create support --email support@mycompany.com --capabilities "inbox.read,email.send"

# Retrieve latest OTP code
npx agentbox-mail otp agent@yourdomain.com

# Launch Web Dashboard
npx agentbox-mail ui

2. Native Electron Desktop App

# Clone the repository
git clone https://github.com/RABNEER/AgentBox.git
cd AgentBox

# Install dependencies and start Desktop App
npm install
npm run app

3. High-Speed Rust Core Daemon

# Build the optimized production binary
cargo build --release

# Start all-in-one daemon (HTTP Port 3000 + SMTP Port 2525)
./target/release/agentbox-mail server --port 3000

<br/>


🏗️ Architecture

                                  ┌───────────────────────────┐
                                  │   Inbound Emails & Tasks  │
                                  └─────────────┬─────────────┘
                                                │
                 ┌──────────────────────────────┼──────────────────────────────┐
                 │                              │                              │
                 ▼                              ▼                              ▼
     ┌───────────────────────┐      ┌───────────────────────┐      ┌───────────────────────┐
     │ Hostinger / Titan /   │      │ Raw SMTP Listener     │      │ Inbound HTTP Webhook  │
     │ Google IMAP TLS (993) │      │ (0.0.0.0:2525)        │      │ (POST /v1/inbound)    │
     └───────────┬───────────┘      └───────────┬───────────┘      └───────────┬───────────┘
                 │                              │                              │
                 └──────────────────────────────┼──────────────────────────────┘
                                                │
                                                ▼
                                 ┌─────────────────────────────┐
                                 │   High-Speed Parser Engine  │
                                 │  • 4–8 Digit OTP Isolator   │
                                 │  • Link Safety Engine       │
                                 │  • TaskDetector (Work Order)│
                                 └──────────────┬──────────────┘
                                                │
                                                ▼
                                 ┌─────────────────────────────┐
                                 │ Embedded SQLite Storage     │
                                 │       (`agentbox.db`)       │
                                 │  • Identities & Auth Tokens │
                                 │  • Mailboxes & Messages     │
                                 │  • Resource Ownership Graph │
                                 │  • Agent Tasks & Audit Logs │
                                 └──────────────┬──────────────┘
                                                │
                 ┌──────────────────────────────┼──────────────────────────────┐
                 │                              │                              │
                 ▼                              ▼                              ▼
     ┌───────────────────────┐      ┌───────────────────────┐      ┌───────────────────────┐
     │ Realtime SSE Bus      │      │ MCP Server (stdio)    │      │ Native Desktop App /  │
     │ (`GET /v1/events`)    │      │ Full Tool Interface   │      │ Web Dashboard (:3000) │
     │ (Live Daemon Bridge)  │      │ Object-Level Auth     │      │                       │
     └───────────────────────┘      └───────────────────────┘      └───────────────────────┘

<br/>


📄 License

Distributed under the MIT License. See LICENSE for more information.

<div align="center">

Built with 🖤 by RABNEER & The AgentBox Open Source Community

</div>

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选