Atlas / MCP servers / deciduus / Calendar

CalendarSAFE

mcp/deciduus/calendar-2

Google Calendar MCP server: 23 tools for LLM agents. Install with uvx calendar-mcp-server.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
—
Transport
stdio · streamable-http
License
NOASSERTION
Stars
26
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP server that gives an LLM client read and write access to your Google Calendar. It runs as a single process — stdio by default, streamable HTTP optionally — and exposes 23 tools with structured output: listing and searching calendars and events, creating, updating, moving, RSVPing to and deleting events, free/busy queries, busyness analysis, recurring-event projection, and finding a mutual slot and booking it. On top of that it has a scheduling brain that knows your working hours: finding and booking focus time, detecting double-bookings across several accounts at once, proposing better times for a meeting, and auditing where your week actually went. Authentication is Google OAuth 2.0 (Desktop app flow); tokens are cached locally, per account, and refreshed automatically.

A calendar task, end to end

Synthetic example, backed by offline tests; no real calendar data or live booking. Assume Thursday working hours of 09:00–17:00 UTC, one meeting at 11:00–12:00, no lunch or buffer, and a 60-minute minimum focus block.

“Find six hours of focus time on January 1, 2026. Show me the blocks first.”

An MCP client can call:

{
"tool": "block_focus_time",
"arguments": {
"time_min": "2026-01-01T00:00:00Z",
"time_max": "2026-01-02T00:00:00Z",
"hours_needed": 6,
"dry_run": true
}
}

The preview selects 09:00–10:00 and 12:00–17:00: six hours, with the last selected block trimmed to the remaining hour. Both events have created: false. After the user approves the times, the client can call with dry_run: false; availability is read again before creating events. A preview does not reserve a slot.

Design decision: unknown availability is not free time. If a checked calendar returns an access error, disappears from the response, or has unreadable busy intervals, focus search and booking return an error before writing anything. The same check protects mutual scheduling and reschedule suggestions/application. For

Read from source at commit e282f31f70f1OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add calendar-mcp-server --env GOOGLE_CLIENT_SECRET=${GOOGLE_CLIENT_SECRET} -- uvx calendar-mcp-server==1.1.1
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (4)

MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
calendar_mcp/server.py:539
module = importlib.import_module(f"calendar_mcp.tools.{submodule}")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:115
The MCP endpoint is then `http://127.0.0.1:8000/mcp` (change the path with `--path`).
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:117
**There is no authentication layer on the HTTP transport yet.** Anyone who can reach the endpoint gets full access to the calendar the saved token belongs to. Bind it to loopback, or expose it only be

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha e282f31f70f1full audit observations/trust-audit/mcp-server/deciduus__calendar-2.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08e282f31f70f1SAFEB89first audit
05

Questions

What is the Calendar MCP server?

Google Calendar MCP server: 23 tools for LLM agents. Install with uvx calendar-mcp-server.

Is Calendar safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Calendar need?

It reads CALENDAR_MCP_ALLOW_BROWSER_AUTH, GOOGLE_CLIENT_SECRET, OAUTH_CALLBACK_PORT and TOKEN_FILE_PATH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Calendar run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as calendar-mcp-server.

How current is this page?

The grade is for one exact copy of the source (e282f31f70f1), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement