steve 5c7dd252db test(cli): prove agent key cannot run admin commands
Initialize a DB, drop EMCLI_ADMIN_KEY, attempt every admin command with
only EMCLI_KEY: each is refused and the DB is byte-for-byte unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-22 23:03:17 +01:00

emcli

A single command-line program that mediates all email access for an AI agent. The agent never holds your email password and never talks to the mail server directly — every read and send goes through emcli, which enforces the limits you configure (read-only/read-write, sender and recipient whitelists, subject filters). Even with faulty instructions, the agent can't read mail it isn't permitted to see or send mail to people it isn't permitted to contact.

Getting started

export EMCLI_KEY="$(head -c 32 /dev/urandom | base64)"   # one-time: generate & save a key
emcli init                                                # create the DB, add your first account
emcli doctor                                              # confirm it connects and authenticates

Documentation

See the User Manual for full setup, account configuration (including Gmail app passwords), the agent and admin command reference, the JSON output format, and troubleshooting.

For AI agents, skills/emcli is an Agent Skill that teaches an agent to read and send mail through emcli, including a binary installer.

S
Description
Email client sandbox CLI for use by Agentic SKILLS
Readme 528 KiB
v0.5.2 Latest
2026-06-23 23:05:49 +01:00
Languages
Go 97.1%
Shell 1.8%
Makefile 1.1%