Other formats agents might prefer:
markdownjsonllms.txt

Agent? You probably want markdown or json, or Pod over MCP.

Reported issues for mcp

Pod holds 11 of 11 problems reported by people outside the maintainer team. Issues filed by the project's own owners, members and collaborators are excluded entirely — a maintainer's release checklist is not a warning to a prospective user.

Back to mcp.

Most discussed

feature: parent-child task relationships for agent delegation

What problem does this solve for you?

Current email-backed tasks model a conversation between two participants. A coordinating agent often needs to delegate parts of its task to other agents and then combine their results.

Today those child tasks are independent. The dashboard cannot answer:

  • Which original task caused this work?
  • Which subtasks remain incomplete?
  • Is a parent blocked by one child?
  • What chain of delegation produced a result?

Users must encode relationships in subject

Read the thread · 2026-08-20 · closed · external user · 3 comments

feature: typed, tamper-evident human approval tasks

What problem does this solve for you?

OpenAgentEmail tasks can enter input-required, and a human can respond through the dashboard. That works for clarification, but a free-form reply is not sufficient when an agent needs authorization for a sensitive action such as sending an external email, publishing a change, modifying infrastructure, or issuing a refund.

A reply such as “looks good” does not establish exactly which action and arguments were approved. The requesting agent could also r

Read the thread · 2026-08-20 · closed · external user · 3 comments

Create a docker-compose with no mail-server

Would be great to deploy this with my cloud mailserver. Can you create a docker compose that just packages API/MCP? would love to deploy easily from portainer

Read the thread · 2026-07-30 · closed · external user · 2 comments

follow-up(#56): version lease-fence error semantics

Follow-up from #56 and PR #77 (merged as a6a58041db1d2748715433ece472828592e5f142).

Review binding: PR77-ZCODE-P2-2 (current-head ZCode report).

Problem

The actor-aware lease fence deliberately reuses task_already_terminal when the recipient lacks the current active lease credential. This makes clients and telemetry unable to distinguish a terminal-state conflict from a lease-fencing conflict.

This b

Read the thread · 2026-08-25 · closed · outside contributor · 1 comment

feature: task claim and lease semantics for multi-worker identities

What problem does this solve for you?

An identity token authorizes an agent identity, but it does not distinguish multiple worker processes operating as that identity. If two workers poll the same task, both may begin work. If a worker crashes after marking a task working, another worker cannot safely determine whether the work is still owned, abandoned, or safe to retry.

Read/unread and task state are useful human-facing signals, but they are not an atomic work-ownership protocol.

This

Read the thread · 2026-08-20 · closed · external user · 1 comment

mail_send: structuredContent fails outputSchema validation in strict hosts (MCP -32602), mail still queued

Summary

mail_send returns MCP error -32602: Structured content does not match the tool's output schema: data must NOT have additional properties to strict MCP clients. The email is actually queued and delivered — this is a validation-layer false failure, not a delivery failure.

Environment

  • MCP client package: @openagentemail/mcp@0.5.1 (also reproduces on 0.5.0)
  • Server: self-hosted, reports serverInfo.version: 0.5.1
  • Client runtime: Kimi CLI (validates structuredContent ag

Read the thread · 2026-08-15 · closed · outside contributor · 1 comment

MCP tool calls (mail_list_identities, mail_new_identity, and likely all /v1/*-backed tools) 404 via loopback despite the same route working over real HTTP

Area

MCP server (agent tools)

Steps to reproduce

Deploy openagent-api behind Caddy + Cloudflare Tunnel, with MCP_PUBLIC_URL set to the public origin (e.g. https://example.com).

Call /v1/identities directly against the API container, bypassing all proxies: Result: 200 OK with real identity data

Call the equivalent MCP tool via /mcp, same host, same token: event: message data: {"result":{"content":[{"type":"text","text":"Not found (404): 404 Not Found. Verify the address/id — list

Read the thread · 2026-08-22 · closed · external user · 0 comments

api: watcher logs untrusted err.message unbounded (server-controlled string)

From PR #40 review ledger (debt 5/5, ZCode P2).\n\nIMAP server errors feed err.message straight into watcher logs without length truncation. A malicious/compromised upstream can inject arbitrarily long strings into logs.\n\nAcceptance:\n- [ ] Truncate err.message to a bounded length at log sites in the watcher path\n- [ ] Unit test covers truncation

Read the thread · 2026-08-18 · closed · outside contributor · 0 comments

Most recent

api: notification-watcher livelock — publish failure keeps watermark stuck, refetches same message every 3s

From PR #40 review ledger (debt 2/5).\n\npackages/api/src/lib/notification-watcher.ts ~line 1283: exceptions from dispatch.publish other than notify_cancelled propagate, the whole batch round fails, the UID watermark never advances → reconnect in 3s → fetch the same message → throw again. Process stays alive (heartbeat OK) but notification delivery is permanently stalled.\n\nAcceptance:\n- [ ] Skip-and-continue (or equivalent) so one bad message cannot block the watermark forever; log the

Read the thread · 2026-08-18 · closed · outside contributor · 0 comments

api: withInbox() lacks ImapFlow 'error' listener — same defect class as #39 (REST/MCP mail paths)

From PR #40 review ledger (debt 1/5).\n\npackages/api/src/lib/imap.ts withInbox() opens ImapFlow connections without attaching a 'error' listener. Same defect class as #39: an async socket error on a connected socket with no listener throws into the event loop and can kill the whole process. All REST/MCP mail read paths go through it.\n\nAcceptance:\n- [ ] Attach error listener with the same pattern as the #39 fix in the watcher\n- [ ] Negative control test: remove listener only → target t

Read the thread · 2026-08-18 · closed · outside contributor · 0 comments

compat: npm @openagentemail/mcp 0.5.0 outputSchema 落后 API(messages source 字段 + detail/summary 拆分)→ 下次发版消化

现象

严格校验 structured output 的 MCP 客户端(如 Kimi Code)用 npm @openagentemail/mcp@0.5.0(stdio)连当前 API(main ≥ 7ebe3c3)时:

  • mail_list_messages 报错:must NOT have additional properties(0.5.0 的 summary schema 未声明 API 已返回的 source / hasOtp
  • mail_read_message 报错:seen: expected boolean, received undefined; snippet: expected string, received undefined(0.5.0 的 detail schema 仍要求 seen/snippet,而 API 早已把这两个字段划给 list-only)

根因

0.5.0 发版(2026-08-10)后,API 侧消息模型继续演进:#23 给消息加 source(internal/extern

Read the thread · 2026-08-12 · closed · outside contributor · 0 comments

The remaining reports are on the project's issue tracker.