npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

anonsec-mcp-server

v1.0.0

Published

Firefox Relay MCP Server for Anonymous Email Management

Readme

License: MIT Node.js TypeScript MCP

// crafted for the security community — funding keeps it maintained

GitHub Sponsors Open Collective Ko-fi Buy Me a Coffee thanks.dev


Overview

Firefox Relay MCP Server (anonsec-mcp-server) is a production-grade Model Context Protocol server that provides comprehensive anonymous email management capabilities through Firefox Relay addresses. Built with privacy, security, and operational excellence as core principles, this server enables AI agents and applications to send, receive, and process emails while maintaining complete anonymity.

Core Value Proposition

  • Privacy-First: All email operations maintain sender anonymity through Firefox Relay infrastructure
  • PQC-Ready: Post-Quantum Cryptography ready encryption architecture for data at rest
  • Production-Grade: Built with golden-standard programming practices for reliability and security
  • MCP Native: Full Model Context Protocol 2.0 compliance with tools and resources

Quick Start

Prerequisites

  • Node.js >= 18.0.0
  • npm or yarn
  • Firefox Relay account and API access

Installation

# Clone the repository
git clone https://github.com/VRIL-LABS/anonsec-mcp-server.git
cd anonsec-mcp-server

# Install dependencies
npm install

# Build the project
npm run build

# Start the server
npm run dev

Configuration

Create a .env file with your Firefox Relay credentials:

FIREFOX_RELAY_API_KEY=your_api_key_here
ENCRYPTION_KEY=your_32_byte_hex_key_here
DATABASE_PATH=./data/anonsec.sqlite
PORT=3000

The encryption key must be exactly 32 bytes (64 hex characters). Generate one with:

node -e "console.log(require('crypto').randomBytes(32).toString('hex'))"

Capabilities

Email Management

  • List new/unread emails from Firefox Relay addresses
  • Read full email content with decryption
  • Retrieve all emails with filtering
  • Get latest email from any relay address

OTP Handling

  • Extract OTP codes from emails
  • Validate OTP format and confidence
  • Check OTP expiration
  • Re-extract OTP from email body

Email Sending

  • Send anonymous emails through relay addresses
  • Support for plain text and HTML content
  • Custom headers and metadata
  • OTP email simulation

Project Structure

.
├── src/
│   ├── index.ts          # Server entry point and configuration
│   ├── api/
│   │   └── index.ts      # Firefox Relay API client
│   ├── config/
│   │   └── index.ts      # Configuration management
│   ├── db/
│   │   └── index.ts      # SQLite database service
│   ├── tools/
│   │   ├── all_emails.ts
│   │   ├── latest_email.ts
│   │   ├── latest_email_otp.ts
│   │   ├── new_emails.ts
│   │   ├── read_emails.ts
│   │   └── send_anon_email.ts
│   ├── types/
│   │   └── index.ts      # Type definitions
│   └── utils/
│       ├── crypto.ts     # Encryption utilities
│       └── otp.ts        # OTP extraction utilities
├── package.json
├── tsconfig.json
├── LICENSE
└── README.md

Tools

The server provides 6 MCP tools:

  1. new_emails - Retrieve new/unread emails
  2. read_emails - Read full email content
  3. all_emails - List all emails with filtering
  4. latest_email - Get the latest email
  5. latest_email_otp - Extract OTP from latest email
  6. send_anon_email - Send anonymous emails

Resources

  • urn:anonsec:relay/addresses - Firefox Relay address management
  • urn:anonsec:email/collection - Email collection access
  • urn:anonsec:otp/emails - OTP emails collection
  • urn:anonsec:server/info - Server information
  • urn:anonsec:audit/logs - Audit logs
  • urn:anonsec:email/{emailId} - Individual email access

Security Features

  • AES-256-GCM Encryption for data at rest
  • Immutable audit logs for all operations
  • Request ID tracking for traceability
  • Security validation for sensitive operations
  • OTP code masking in responses (never exposed)
  • Sensitive data redaction in audit logs

Architecture

The server follows a clean, production-ready architecture:

  1. MCP Server Layer - Server initialization, tool registration, request handling
  2. Tools Layer - Individual tool implementations
  3. Core Services Layer - Database, API client, configuration, types, utilities
  4. Data Layer - SQLite database with PQC-ready encryption

Contributing

Contributions are welcome! See CONTRIBUTING.md for guidelines.

Security

See SECURITY.md for vulnerability reporting and security practices.

License

This project is licensed under the MIT License - see LICENSE for details.