No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by andrefetch · MCP Server · ★ 126
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is postal safe to install? View the security audit →
Postal An open-source AI coding agent that lives in your terminal. Plans, edits, runs, and reviews code with any model on OpenRouter. Postal connects to LLMs through OpenRouter, reads and edits your code with a built-in tool set, runs shell commands, delegates to specialized sub-agents, and streams everything through a full-screen TUI. Every mutating action goes through an approval policy you control, so it is as autonomous or as careful as you want it to be. Quickstart ↴ Two commands and you are talking to an agent in your own repo: More ways to run it: Configuration lives in , with per-project overrides in , and is picked up automatically. Full CLI reference | configuration reference Do
| Stars | 126 |
| Forks | 33 |
| Language | Python |
| Category | MCP Server |
| License | GPL-3.0 |
| Quality Score | 64.6999807531209/100 |
| Open Issues | 8 |
| Last Updated | 2026-09-20 |
| Created | 2026-06-26 |
| Platforms | cli, mcp, python |
| Est. Tokens | ~16k |
These tools work well together with postal for enhanced workflows:
Looking for a postal alternative? If you're comparing postal with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Open source AI coding platform with Web IDE, multi-agent system, 37+ tools, MCP protocol. MIT licensed.
Penpot MCP server
All-in-one MCP server that can connect your AI agents to any native endpoint, powered by UTCP
MCP Server for Facebook ADs Library - Get instant answers from FB's ad library
Regression testing for AI agents. Snapshot behavior,diff tool calls,catch regressions in CI. Works with LangGr
Automated loop driver, slash commands, council automation, MCP browser bridge, and portfolio governance for Cl
Explore other popular mcp server tools:
postal is An open-source, terminal-based AI coding agent that reads your code, calls tools, and helps you build.. It is categorized as a MCP Server with 126 GitHub stars.
postal is primarily written in Python. It covers topics such as agentic-ai, ai, cli.
You can find installation instructions and usage details in the postal GitHub repository at github.com/andrefetch/postal. The project has 126 stars and 33 forks, indicating an active community.
postal is released under the GPL-3.0 license, making it free to use and modify according to the license terms.
The top alternatives to postal on Agent Skills Hub include claude-code-open, penpot-mcp, utcp-mcp. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: