MCP servers for team chat, email, video, meetings and real-time collaboration tools. Each entry is scanned with the deterministic Capability-Flow Trust Model — grades are computed, never self-reported.
Security scan results for the Metabase MCP server.
Security scan results for the Mobile MCP server.
Security scan results for the Datetime MCP server.
Security scan results for the Mui MCP server.
Security scan results for the Growthbook MCP server.
Security scan results for the Email Client MCP server.
Security scan results for the Ours.network MCP server.
Security scan results for the Instantdb MCP server.
Security scan results for the Extension.dev MCP server.
Security scan results for the Plugin Mcp Chat Backend MCP server.
Security scan results for the Plugin Mcp Chat MCP server.
Security scan results for the Auth MCP server.
Security scan results for the Imap MCP server.
Security scan results for the Mail MCP server.
Security scan results for the Better Email MCP server.
Security scan results for the Hypermail MCP server.
Security scan results for the Hypertool MCP server.
Security scan results for the Withone MCP server.
Security scan results for the Dovetail MCP server.
Security scan results for the Agent Recall MCP server.
Security scan results for the Wc26 MCP server.
Security scan results for the Instantly MCP server.
Security scan results for the Telegram MCP server.
Security scan results for the Discord MCP server.
When an assistant like Claude or Cursor summarizes a Slack thread or drafts an email, a Model Context Protocol connector is doing the plumbing. A communication MCP server sits between the model and your workspace tools — team chat platforms such as Slack, Microsoft Teams and Discord, mailboxes on Gmail or Outlook, meeting and video suites like Zoom and Google Meet, plus the calendars behind them. It stores the OAuth token or API key, exposes a fixed set of actions (search mail, read a channel, post a message, book a slot), and executes whatever the assistant requests within those scopes.
The security stakes in this category are unusually high. Messaging scopes tend to be broad, so a malicious or over-permissioned server could read entire DM histories and mail archives, quietly forward them elsewhere, or send messages that appear to come from you. Email is also the recovery channel for nearly every other account — including the payment platforms under Finance & Commerce — so inbox access can escalate into account takeover. And every incoming message is untrusted text: a stranger's email can smuggle instructions aimed at the model, a risk that compounds when paired with AI, Memory & Reasoning servers that persist what the assistant reads.
Each listing here therefore carries a Trust Score produced by the deterministic mcptrustchecker engine — a rule-based pass over the published package that maps its real blast radius, documented under how the scoring works. Compare graded options across the MCP Trust Registry before wiring anything into a live inbox.
It can be, if you treat the server like any privileged integration. Prefer packages with a strong Trust Score and narrow scopes — read-only where possible — and review outbound messages before they go out. Avoid servers whose findings show network calls or permissions unrelated to their stated purpose.