Google WorkspaceSAFE
MCP Server for Gmail and Calendar
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol server for Google Workspace services. This server provides tools to interact with Gmail and Google Calendar through the MCP protocol.
Features
- Multiple Google Account Support
- Use and switch between multiple Google accounts
- Each account can have custom metadata and descriptions
- Gmail Integration
- Query emails with advanced search
- Read full email content and attachments
- Create and manage drafts
- Reply to emails
- Archive emails
- Handle attachments
- Bulk operations support
- Calendar Integration
- List available calendars
- View calendar events
- Create new events
- Delete events
- Support for multiple calendars
- Custom timezone support
Example Prompts
Try these example prompts with your AI assistant:
Gmail
- "Retrieve my latest unread messages"
- "Search my emails from the Scrum Master"
- "Retrieve all emails from accounting"
- "Take the email about ABC and summarize it"
- "Write a nice response to Alice's last email and upload a draft"
- "Reply to Bob's email with a Thank you note. Store it as draft"
Calendar
- "What do I have on my agenda tomorrow?"
- "Check my private account's Family agenda for next week"
- "I need to plan an event with Tim for 2hrs next week. Suggest some time slots"
Prerequisites
- Node.js >= 20
- A Google Cloud project with Gmail and Calendar APIs enabled
- OAuth 2.0 credentials for Google APIs
Installation
- Clone the repository:
git clone https://github.com/j3k0/mcp-google-workspace.git cd mcp-google-workspace
- Install dependencies:
npm install
- Build the TypeScript code:
npm run build
Configuration
OAuth 2.0 Setup
Google Workspace (G Suite) APIs require OAuth2 authorization. Follow these steps to set up authentication:
- Create OAuth2 Credentials:
- Go to the [Google Cloud Console](https://console.cloud.google.
a74b8b151912OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-gmail -- npx -y [email protected]
{
"mcpServers": {
"mcp-gmail": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (15)
11 read · 2 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
calendar_create_event | write | Creates a new event in the specified Google Calendar. |
calendar_delete_event | destructive | Deletes an event from the specified Google Calendar. |
calendar_get_events | read | Retrieves calendar events from the user\ |
calendar_list | read | Lists all calendars accessible by the user. Call it before any other tool whenever the user specifies a particular agenda (Family, Holidays, etc.). Returns detailed calendar metadata including access roles and timezone information. |
calendar_list_accounts | read | Lists all configured Google accounts that can be used with the calendar tools. This tool does not require a user_id as it lists available accounts before selection. |
gmail_archive | read | Archives a Gmail message by removing it from the inbox. |
gmail_bulk_archive | read | Archives multiple Gmail messages by removing them from the inbox. |
gmail_bulk_get_emails | read | Retrieves multiple Gmail email messages by their IDs in a single request, including the full message bodies and attachment IDs. |
gmail_bulk_save_attachments | write | Saves multiple Gmail attachments to disk by their message IDs and attachment IDs in a single request. |
gmail_delete_draft | destructive | Deletes a Gmail draft message by its ID. This action cannot be undone. |
gmail_get_attachment | read | Retrieves a Gmail attachment by its ID. |
gmail_get_email | read | Retrieves a complete Gmail email message by its ID, including the full message body and attachment IDs. |
gmail_list_accounts | read | Lists all configured Google accounts that can be used with the Gmail tools. This tool does not require a user_id as it lists available accounts before selection. |
gmail_list_drafts | read | Lists Gmail drafts for the user. Returns each draft |
gmail_query_emails | read | Query Gmail emails based on an optional search query. Returns emails in reverse chronological order (newest first). Returns metadata such as subject and also a short summary of the content. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
calendar_delete_event, gmail_delete_draft
@modelcontextprotocol/sdk, dotenv, googleapis, marked, open, @types/node, ts-node, typescript
Gates applied: no_behavioural_pass.
a74b8b151912full audit observations/trust-audit/mcp-server/j3k0__google-workspace.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | a74b8b151912 | SAFE | B | 89 | first audit |
Questions
What is the Google Workspace MCP server?
MCP Server for Gmail and Calendar
What tools does Google Workspace expose?
15 in total: 11 read-only, 2 that write, and 2 that can delete or overwrite (calendar_delete_event, gmail_delete_draft). Every one is listed on this page with its risk.
Is Google Workspace safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Google Workspace need?
No credential environment variables were found in its source, so it appears to need none.
How does Google Workspace run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-gmail at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (a74b8b151912), read on 2026-10-08. The repository is watched and re-audited when it changes.