← Back to archive

Repo of the Day

CyrisXD/agent-notify

Published: Oct 6, 2026

Open repository ↗

Let Claude, ChatGPT, Grok Bot and any MCP agent email you when something needs your attention. Private, free, one-click deploy to Cloudflare Workers

Summary

agent-notify is a single Cloudflare Worker, written in TypeScript and MIT licensed, that lets AI agents and scripts send email to a fixed recipient — the deployer — without touching their inbox. It deploys in one click and runs on the user's own Cloudflare account, with no shared service in the middle.

What it is useful for

This is for engineers who run background or always-on agents (Claude Code, Cursor, Grok Bot, ChatGPT, OpenAI Dots, anything that speaks MCP) and want a push channel back to themselves when something needs attention. The README's examples are concrete: a new lead arriving in the inbox, a weekly digest of free games on Epic, a failed backup, a finished long-running report. Because the recipient is locked in at deploy time, callers cannot pick who receives the message, so a misbehaving or prompt-injected agent cannot use it to email secrets to an attacker.

A companion "skill" is shipped as a plain Markdown file (skills/agent-notify/SKILL.md) that teaches an agent when to email (only on what the user asked it to watch for, failures, decisions waiting on the user, finished long jobs) and how to write alerts: short and clear for failures, longer and itemized for digests. The skill also tells agents never to include passwords or tokens in messages and to stop rather than retry when a send limit is hit.

How engineers can use it

Setup requires a free Cloudflare account, a domain on Cloudflare, and any inbox. The README's documented path:

  1. Onboard the domain for sending in the Cloudflare dashboard, then verify the destination inbox under Destination addresses.
  2. Deploy via the Deploy to Cloudflare button, supplying a worker name with a random suffix, TO_ADDRESS (the verified inbox), and FROM_ADDRESS (anything on the onboarded domain).
  3. Open the one-time setup link emailed to that inbox, click Reveal, and save the bearer token. That page is shown once.

After that, any script can send by POSTing JSON with the token:

curl -X POST "$AGENT_NOTIFY_URL" \
  -H "Authorization: Bearer $AGENT_NOTIFY_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"subject":"Backup finished","text":"All 3 databases backed up."}'

For Claude Code, the README documents installing the skill with one curl command into ~/.claude/skills/agent-notify/, then asking in plain language ("email me when it's done") or invoking /agent-notify. ChatGPT, Grok Bot, and other apps use the secret MCP URL as a custom connector with no authentication.

Documented limits: on the free plan, going over a limit pauses sending until the next day. On the $5 Workers Paid plan, HOURLY_LIMIT defaults to 20 and DAILY_LIMIT to 100, and the README recommends setting a Cloudflare budget alert. The README is explicit that agent-notify cannot fully prevent prompt injection — it only limits the blast radius — and advises treating any agent-notify email asking the user to log in, pay, or run a command as phishing.