Atlas / MCP servers / dguido / Google Workspace

Google WorkspaceCAUTION

mcp/dguido/google-workspace-13

MCP server for Google Drive, Docs, Sheets, Slides, Calendar, Gmail, and Contacts

Verdict
CAUTION
Grade
B
Trust score
81 /100
Exposed tools
71 25r · 32w · 14d
Transport
stdio
License
MIT
Stars
38
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

MCP server providing Claude access to Google Drive, Docs, Sheets, Slides, Calendar, Gmail, and Contacts.

Quick Start

1. Set Up Google Cloud

  1. Go to the Google Cloud Console and create or select a project
  2. Enable all required APIs (one-click link)
  3. Go to APIs & Services > Credentials and create an OAuth 2.0 Client ID (Desktop app type)
  4. Copy the Client ID and Client Secret

2. Configure Claude Desktop

macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%\Claude\claude_desktop_config.json

{
"mcpServers": {
"google-workspace": {
"command": "npx",
"args": ["@dguido/google-workspace-mcp"],
"env": {
"GOOGLE_CLIENT_ID": "YOUR_CLIENT_ID.apps.googleusercontent.com",
"GOOGLE_CLIENT_SECRET": "YOUR_CLIENT_SECRET",
"GOOGLE_WORKSPACE_SERVICES": "drive,gmail,calendar"
}
}
}
}

That's it. On first tool call, a browser window opens for Google OAuth consent. Tokens are saved automatically.

Alternative: file-based credentials

Download the credentials JSON from Google Cloud Console and save to ~/.config/google-workspace-mcp/credentials.json, then authenticate manually:

npx @dguido/google-workspace-mcp auth

See Advanced Configuration for file-based setup, named profiles, and multi-account setup.

What You Can Do

Create a Google Doc called "Project Plan" in /Work/Projects with an outline for Q1.
Search for files containing "budget" and organize them into the Finance folder.
Create a presentation called "Prod
Read from source at commit 8cbe02646512OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add google-workspace-mcp --env GOOGLE_CLIENT_SECRET=${GOOGLE_CLIENT_SECRET} --env GOOGLE_WORKSPACE_MCP_TOKEN_PATH=${GOOGLE_WORKSPACE_MCP_TOKEN_PATH} -- npx -y @dguido/[email protected]
claude-desktop
{
  "mcpServers": {
    "google-workspace-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@dguido/[email protected]"
      ],
      "env": {
        "GOOGLE_CLIENT_SECRET": "${GOOGLE_CLIENT_SECRET}",
        "GOOGLE_WORKSPACE_MCP_TOKEN_PATH": "${GOOGLE_WORKSPACE_MCP_TOKEN_PATH}"
      }
    }
  }
}
03

Exposed tools (71)

25 read · 32 write · 14 destructive. Blast radius: 14 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
actionreadAction to take:
add_google_sheet_conditional_formatwriteAdd conditional formatting to a Sheet
append_to_docreadAppend text to the end of a Google Doc
backup-folderreadExport all files in a folder to a local directory. Google Docs are exported as their native formats.
batch_deletedestructiveBatch move files to trash (max 100 per batch)
batch_movewriteBatch move files to folder (max 100 per batch)
batch_restorereadBatch restore files from trash (max 100 per batch)
batch_sharereadBatch share files with a user (max 100 per batch)
cleanup-old-filesdestructiveFind and optionally delete files older than a specified number of days.
copy_filereadCopy a file with optional new name
create_contactwriteCreate a new contact
create_eventwriteCreate a new calendar event
create_filewriteCreate file (auto-detects type from name)
create_filterwriteCreate an email filter
create_folderwriteCreate a new folder in Google Drive
create_google_docwriteCreate a new Google Doc
create_google_sheetwriteCreate a new Google Sheet
create_google_slideswriteCreate a new Google Slides presentation
create_google_slides_shapewriteCreate a shape in Google Slides
create_google_slides_text_boxwriteCreate a text box in Google Slides
create_text_filewriteCreate a text or markdown file
daysOldreadMinimum age in days for files to be considered old
delete_contactdestructiveDelete a contact
delete_draftdestructivePermanently delete one or more drafts by ID (max 100).
delete_emaildestructiveDelete emails permanently (max 1000 IDs per request)
delete_eventdestructiveDelete a calendar event
delete_filterdestructiveDelete an email filter
delete_itemdestructiveMove items to trash
delete_labeldestructiveDelete a user-created label
delete_text_in_docdestructiveDelete text range from a Google Doc
draft_emailwriteCreate or update a draft email. Omit draftId to create new;
emailsreadComma-separated list of email addresses
empty_trashdestructivePermanently delete all files in trash
fileIdsreadComma-separated list of file IDs to share
fileTypesreadComma-separated file types to convert: doc, xls, ppt (or
folderIdreadThe ID of the folder to organize (use
format_google_doc_rangereadFormat text and paragraphs in a Doc
format_google_sheet_cellsreadFormat cells in a Google Sheet
format_slide_backgroundwriteSet slide background color in Google Slides
format_slides_shapereadFormat shape fill and outline in Google Slides
format_slides_textreadFormat text styling in Google Slides
get_or_create_labelwriteGet or create a Gmail label
insert_text_in_docwriteInsert text at a position in a Doc
localPathwriteLocal directory path to save the backup
merge_google_sheet_cellswriteMerge cells in a Google Sheet
migrate-formatreadConvert Office files to Google Workspace formats for editing, or convert legacy binary formats (.doc, .xls, .ppt) for reading.
modify_emaildestructiveAdd/remove labels on threads (max 1000 IDs per request)
move_itemwriteMove items to a new folder
organize-folderreadOrganize files in a folder by type or date. Creates subfolders and moves files accordingly.
organizeByreadHow to organize:
remove_permissiondestructiveRemove sharing permission from a file
rename_itemwriteRename a file or folder
replace_text_in_docreadFind and replace text in a Doc
restore_from_trashreadRestore a file from trash
restore_revisionreadRestore file to previous revision
rolereadPermission role: reader, commenter, or writer
send_emailwriteSend an email
share-with-teamreadShare multiple files with a list of email addresses with specified permissions.
share_filereadShare a file with a user, group, domain, or make public
sheet_tabsdestructiveManage tabs in a spreadsheet: list, create, delete, or rename
slides_speaker_noteswriteGet or update speaker notes for a slide
star_filereadStar or unstar a file in Google Drive
update_contactwriteUpdate an existing contact
update_eventwriteUpdate an existing calendar event
update_filewriteUpdate file (auto-detects type)
update_google_docwriteReplace content in a Google Doc
update_google_sheetwriteUpdate a Google Sheet range
update_google_slideswriteUpdate a Google Slides presentation
update_labelwriteUpdate an existing Gmail label
update_text_filewriteUpdate content of a text or markdown file in Google Drive
upload_filewriteUpload file from disk or base64
04

Trust audit

CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (11)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/auth/client.ts:60
redirectUri: credentials.redirect_uris?.[0] || "http://127.0.0.1/oauth2callback",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/utils/logging.test.ts:51
log("service account", { private_key: "-----BEGIN RSA PRIVATE KEY-----\nMIIE..." });
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/utils/logging.test.ts:171
log("debug", { key: "-----BEGIN PRIVATE KEY-----\nMIIE..." });
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
batch_delete, cleanup-old-files, delete_contact, delete_draft, delete_email, delete_event, delete_filter, delete_item, delete_label, delete_text_in_doc, empty_trash, modify_email, remove_permission, s
Why it matters. 14 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.oxlintrc.json
.oxlintrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/TROUBLESHOOTING.md:36
3. Authenticate with Google — the browser redirects to `http://127.0.0.1:<port>/...`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/auth/server.test.ts:40
"http://127.0.0.1:54321/oauth2callback" + "?code=4/0AQSTthis_is_the_code&state=abc123";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/auth/server.test.ts:49
const input = "http://127.0.0.1:54321/oauth2callback" + "?code=4/0AQSTthis_is_the_code";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/auth/server.test.ts:97
const input = "http://127.0.0.1:54321/oauth2callback?error=access_denied";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@toon-format/toon, zod, oxfmt
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 8cbe02646512full audit observations/trust-audit/mcp-server/dguido__google-workspace-13.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-088cbe02646512CAUTIONB81first audit
06

Questions

What is the Google Workspace MCP server?

MCP server for Google Drive, Docs, Sheets, Slides, Calendar, Gmail, and Contacts

What tools does Google Workspace expose?

71 in total: 25 read-only, 32 that write, and 14 that can delete or overwrite (batch_delete, cleanup-old-files, delete_contact, delete_draft, delete_email). Every one is listed on this page with its risk.

Is Google Workspace safe to connect to an agent?

With care. The audit graded it B (81/100) and found 11 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 14 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Google Workspace need?

It reads GOOGLE_CLIENT_SECRET and GOOGLE_WORKSPACE_MCP_TOKEN_PATH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Google Workspace run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @dguido/google-workspace-mcp at 3.4.4.

How current is this page?

The grade is for one exact copy of the source (8cbe02646512), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement