Item detail
github.com

Mnexa-AI/e2a

Mnexa-AI/e2a is a developer tool that RepoRadar is tracking in its Radar section, currently rated Gold tier with a 'try now' verdict. Its strongest signal is workflow potential, scored 10.0 out of 10.

Score8.8
Popularity70.0
Riskmedium
TierGold
Score breakdown
Usefulness9.0
Novelty8.0
Momentum7.0
Maturity8.3
Open-source/build8.4
Evidence7.2
Workflow potential10.0
Setup ease6.4

Popularity is tracked separately. Support, ads, sponsorships, and tips never affect these signals.

Why it matters

Useful for builders who want agents to work through email without turning a shared inbox into a blind trust exercise: it offers a clearer transport and approval model than stitching SMTP, webhooks, and agent logic together by hand.

Who should use it

automation builders support workflow teams developers building agent inboxes operators who need human approval on outbound actions

Who should skip it

Hold off on Mnexa-AI/e2a for mission-critical workflows without a containment strategy, explicit approvals, and a hands-on security review.

About this signal

Mnexa-AI/e2a is tracked by RepoRadar as a developer tool in the Radar section. First seen 2026-06-19; the source record was last checked on 2026-06-19. The current verdict is 'try now' with a Gold tier and moderate setup difficulty. Across RepoRadar's eight signals, Mnexa-AI/e2a is strongest on workflow potential (10.0) and practical usefulness (9.0) and weakest on setup ease (6.4) — a profile worth weighing against your own priorities. This page summarizes the public evidence on the linked source page and states where additional review is still needed.

How this item is evaluated

The Mnexa-AI/e2a record combines a 8.8/10 composite score with separate popularity (70.0), risk (medium), and setup (moderate) signals. See the scoring methodology for the current weights and evidence definitions.

Putting this into practice? Read How to vet an AI agent or MCP server before you wire it in for the checklist behind this score.

Risk explanation

This tool handles real inbound and outbound email for agents, so keep it on test inboxes first and review exactly who can approve, relay, or spoof a message path before broader use.

Evidence links
Closest alternatives / related signals
email agent-workflows human-in-the-loop webhooks authentication
Verification record

What RepoRadar actually verified

Tested in a bounded workflow

Bounded representative workflow retained by RepoRadar verification harness. Last checked 2026-07-14T04:56:01.587164Z.

passed · cohort-20260713-e2a-signed-webhook-verification-workflow

Tester
RepoRadar automated local verification harness
Started
2026-07-14T04:55:58.537157Z
Completed
2026-07-14T04:56:01.587164Z
Environment
Windows 10 AMD64; Python 3.11.9; credential-stripped child environment; disposable home/cache
Install/setup time
1 minute(s)
Evidence scope
Bounded representative workflow
Cleanup
Per-check temporary home and work directory removed. Shared cohort package cache removed.
Actions exercised
  • Created a disposable home, work directory, and isolated package cache with credential-like environment variables excluded.
  • Created 1 synthetic fixture file(s) inside the disposable work directory; retained hashes prove the exact inputs.
  • Built a canonical synthetic execution.completed event and its fixed HMAC-SHA256 signature header.
  • Verified the valid delivery, rejected a payload changed after signing, and rejected the original delivery 301 seconds outside a 300-second replay window.
  • Constructed the typed E2A WebhookEvent and retained only non-secret event fields and boolean verification outcomes.
  • Executed bounded check: Construct and verify a deterministic signed E2A webhook event, then prove tampered payload and replay-window rejection.
  • Captured the complete sanitized stdout, stderr, exit status, artifact checks, and 3.05-second wall time.
Observed results
  • Command exited 0 after 3.05 seconds.
  • E2A accepted the authentic fixed event, parsed its type/id/data, rejected the tampered body, and rejected the stale replay deterministically.
  • Expected marker 'CHECK_OK event=execution.completed valid=true tampered=false replay=false' was observed in retained output.
  • Validated result.json: 5 required marker(s) present and 0 excluded marker(s) absent; size and SHA-256 are retained.
Observed strengths
  • The SDK combines constant-time signature verification, replay-window enforcement, and typed event construction in a small offline handler path.
Friction
  • Webhook callers must preserve the exact raw request bytes and supply their own endpoint secret and clock discipline; this fixture intentionally avoids a live delivery endpoint.
  • Setup or runtime emitted 3 stderr line(s); the complete warnings/errors are preserved in the retained log.
Limitations
  • This exercises the SDK's offline webhook authenticity and parsing path; it does not call E2A's hosted orchestration API, create executions, open WebSockets, test delivery retries, or validate account-level behavior.
  • This credential-free disposable workflow does not establish operator use, production scale, model quality, reliability under sustained use, or team adoption.

Pricing assessment: The offline Python SDK path used no E2A account, hosted execution, provider key, or paid API request.

Privacy assessment: Only a synthetic event and fixture-only HMAC secret existed inside the disposable process; no webhook body, signature, or execution data left the machine.

Open retained test log →

Verification sources

Longitudinal intelligence

How this decision record is moving

Raw history JSON →

46 dated snapshots retained from 2026-06-19 through 2026-08-13; see the snapshot index for explicit coverage gaps. Stars, version, release, pricing, integration, risk, maintenance, verdict, score, and momentum fields remain explicit even when a source has not reported them. Repository momentum is a normalized 0–10 RepoRadar signal; GitHub stars appear only where the popularity monitor retained exact timestamped observations.

RepoRadar score8.8 current · +0.0 net
Repository momentum8.5 current · +1.5 net
GitHub stars (observed)181 current · +9 net
GitHub stars181 exact observation
Versionv1.7.7
Last release2026-08-11T23:54:04Z
Maintenanceactive
Current riskmedium
Current verdicttry now
Pricing baselineNo structured commercial pricing baseline
Pricing checkedNot applicable or not recorded
Pricing freshnessNo dated commercial pricing review
Integrations baselineNo structured integrations recorded

Recent dated points

DateScoreMomentumStarsRiskVerdictMaintenance
2026-08-138.88.5181mediumtry nowactive
2026-08-128.89.0182mediumtry nowactive
2026-08-118.89.0182mediumtry nowactive
2026-08-108.89.0182mediumtry nowactive
2026-08-098.89.0182mediumtry nowactive
2026-08-088.89.0182mediumtry nowactive
2026-08-078.89.3178mediumtry nowactive
2026-08-068.87.0Not recordedmediumtry nownot recorded
2026-08-058.87.0Not recordedmediumtry nownot recorded
2026-08-048.89.3178mediumtry nowactive
2026-08-038.89.3178mediumtry nowactive
2026-08-028.89.0176mediumtry nowactive

Why the record changed

stars changed

Stars changed: 182 → 181.

version changed

Version changed: v1.7.6 → v1.7.7.

version changed

Version changed: v1.6.0 → v1.7.6.

stars changed

Stars changed: 178 → 182.

version changed

Version changed: v1.5.0 → v1.6.0.

stars changed

Stars changed: 176 → 178.

version changed

Version changed: v1.4.1 → v1.5.0.

stars changed

Stars changed: 173 → 177.

version changed

Version changed: v1.0.8 → v1.4.1.

stars changed

Stars changed: 172 → 173.

verification changed

Verification changed: Discovered → Tested in a bounded workflow.