GmailCAUTION
Model Context Protocol (MCP) server for Gmail
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This MCP server integrates with Gmail to enable sending, removing, reading, drafting, and responding to emails.
Note: This server enables an MCP client to read, remove, and send emails. However, the client prompts the user before conducting such activities.
https://github.com/user-attachments/assets/5794cd16-00d2-45a2-884a-8ba0c3a90c90
Components
Tools
- send-email
- Sends email to email address recipient
- Input:
recipient_id(string): Email address of addresseesubject(string): Email subjectmessage(string): Email content- Returns status and message_id
- trash-email
- Moves email to trash
- Input:
email_id(string): Auto-generated ID of email- Returns success message
- mark-email-as-read
- Marks email as read
- Input:
email_id(string): Auto-generated ID of email- Returns success message
- get-unread-emails
- Retrieves unread emails
- Returns list of emails including email ID
- read-email
- Retrieves given email content
- Input:
email_id(string): Auto-generated ID of email- Returns dictionary of email metadata and marks email as read
- open-email
- Open email in browser
- Input:
email_id(string): Auto-generated ID of email- Returns success message and opens given email in default browser
Setup
Gmail API Setup
- Create a new Google Cloud project
- Enable the Gmail API
- Configure an OAuth consent screen
- Select "external". However, we will not publish the app.
- Add your personal email address as a "Test user".
- Add OAuth scope
https://www.googleapis.com/auth/gmail/modify - Create an OAuth Client ID for applicati
3ca482e81b1eOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add gmail -- uvx gmail
{
"mcpServers": {
"gmail": {
"command": "uvx",
"args": [
"gmail"
]
}
}
}Exposed tools (6)
5 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get-unread-emails | read | Retrieve unread emails |
mark-email-as-read | read | Marks given email as read |
open-email | read | Open email in browser |
read-email | read | Retrieves given email content |
send-email | write | |
trash-email | read |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | WARN |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
Integrates with Gmail to enable programmatic sending, reading, and management of emails
images/demo.mov
Gates applied: no_behavioural_pass.
3ca482e81b1efull audit observations/trust-audit/mcp-server/jasonsum__gmail-5.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 3ca482e81b1e | CAUTION | B | 89 | first audit |
Questions
What is the Gmail MCP server?
Model Context Protocol (MCP) server for Gmail
What tools does Gmail expose?
6 in total: 5 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Gmail safe to connect to an agent?
With care. The audit graded it B (89/100) and found 2 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Gmail need?
No credential environment variables were found in its source, so it appears to need none.
How does Gmail run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as gmail.
How current is this page?
The grade is for one exact copy of the source (3ca482e81b1e), read on 2026-10-07. The repository is watched and re-audited when it changes.