Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Create Manage Disposable Email Inboxes

BSecurity

Create and manage temporary disposable email inboxes

19 stars
0 votes
0 copies
1 views
Added 9/19/2026
ai-agentsgobashtestinggitapi

Works with

api

Security Analysis

B75/100
criticalExfiltrates credentials via HTTP — exact pattern from Snyk ToxicSkills study
criticalSends environment variables or credentials to an external URL

Scanned 9/19/2026

Install to Claude Code

$npx -y skills add rondoflow/rondoflow --skill create-manage-disposable-email-inboxes --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Create Manage Disposable Email Inboxes?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Create Manage Disposable Email Inboxes
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/rondoflow-create-manage-disposable-email-inboxes/badge)](https://www.skillsdirectory.com/skills/rondoflow-create-manage-disposable-email-inboxes)

More formats (shields.io, HTML) on the badges page.

Download with Pro
Files
SKILL.md
---
name: create-manage-disposable-email-inboxes
description: "Create and manage temporary disposable email inboxes"
category: "Communication"
author: community
version: "1.0.2"
icon: message-circle
---

# Shitty Email - Temporary Inbox Skill

Create disposable email addresses instantly. Perfect for signups, testing, and privacy.

## When to Use This Skill

Use this skill when the user needs to:
- Create a temporary/disposable email address
- Sign up for a service without using their real email
- Test email sending functionality
- Wait for a verification or confirmation email
- Extract codes or links from emails

## Important: Token Management

When you create an inbox, you receive a **token**. This token is required for ALL subsequent operations. Always store and reuse the token for the same inbox session.

## API Reference

Base URL: `https://shitty.email`

### Create a New Inbox

```bash
curl -s -X POST https://shitty.email/api/inbox | jq
```

Response:
```json
{
  "email": "abc1234@shitty.email",
  "token": "a1b2c3d4e5f6..."
}
```

**Store both the email and token** - you need the token for all other operations.

### Check Inbox for Emails

```bash
curl -s -H "X-Session-Token: {token}" https://shitty.email/api/inbox | jq
```

Response:
```json
{
  "emails": [
    {
      "id": "msg_a1b2c3d4e5",
      "from": "sender@example.com",
      "subject": "Welcome!",
      "date": "2026-02-03T12:00:00Z"
    }
  ]
}
```

### Get Full Email Content

Use the `id` field from the inbox response (e.g. `msg_a1b2c3d4e5`). This is NOT the email address.

```bash
curl -s -H "X-Session-Token: {token}" https://shitty.email/api/email/{email_id} | jq
```

Response includes `html` and `text` fields with the email body.

### Extend Inbox Lifetime

Inboxes expire after 1 hour by default. Extend by 1 hour (max 24 hours total):

```bash
curl -s -X POST -H "X-Session-Token: {token}" https://shitty.email/api/inbox/extend | jq
```

### Delete Inbox

Clean up when done:

```bash
curl -s -X DELETE -H "X-Session-Token: {token}" https://shitty.email/api/inbox
```

## Common Workflows

### Wait for a Verification Email

Poll the inbox until an email matching criteria arrives:

```bash
# Create inbox
RESPONSE=$(curl -s -X POST https://shitty.email/api/inbox)
EMAIL=$(echo $RESPONSE | jq -r '.email')
{token}=$(echo $RESPONSE | jq -r '.token')

# Poll for emails (check every 5 seconds, max 60 seconds)
for i in {1..12}; do
  EMAILS=$(curl -s -H "X-Session-Token: ${token}" https://shitty.email/api/inbox)
  COUNT=$(echo $EMAILS | jq '.emails | length')
  if [ "$COUNT" -gt "0" ]; then
    echo "Email received!"
    echo $EMAILS | jq '.emails[0]'
    break
  fi
  sleep 5
done
```

### Extract Verification Code

After receiving an email, extract common verification patterns:

```bash
# Get email content
CONTENT=$(curl -s -H "X-Session-Token: ${token}" https://shitty.email/api/email/${email_id} | jq -r '.text')

# Common patterns to look for:
# - 6-digit codes: grep -oE '[0-9]{6}'
# - Verification links: grep -oE 'https?://[^ ]+verify[^ ]*'
```

## Best Practices

1. **Reuse tokens** - Don't create new inboxes unnecessarily
2. **Poll responsibly** - Wait 5 seconds between checks
3. **Clean up** - Delete inbox when done to free resources
4. **Extend if needed** - If waiting for slow emails, extend the inbox

## Limitations

- Inboxes expire after 1 hour (extendable to 24 hours max)
- Email size limit: 1MB
- Rate limited: Don't spam inbox creation
- No outbound email - receive only

## Example Conversation

User: "Create a temp email for me"
→ Call POST /api/inbox, return the email address, store the token

User: "Sign me up for newsletter.example.com"
→ Use the temp email to fill the signup form, then poll for confirmation

User: "Did I get the confirmation?"
→ Check inbox using stored token, report results

User: "What's the verification code?"
→ Fetch email content, extract the code pattern, return it

User: "I'm done, delete the inbox"
→ Call DELETE /api/inbox with the token

Attribution

rondoflowrondoflow
View sourceMore from rondoflow →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1074701 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

693621 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

691 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →