Atlas / MCP servers / piotr-agier / Google Drive

Google DriveCAUTION

mcp/piotr-agier/google-drive-1

A Model Context Protocol (MCP) server that provides secure integration with Google Drive, Docs, Sheets, Slides and Calendar. It allows Claude Desktop and other MCP clients to manage files in Google Drive through a standardized interface.

Verdict
CAUTION
Grade
B
Trust score
80 /100
Exposed tools
118 54r · 55w · 9d
Transport
stdio · streamable-http
License
MIT
Stars
223
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mcptoplist.com/server/io.github.piotr-agier%2Fgoogle-drive-mcp)

Connect an MCP client to Google Drive, Docs, Sheets, Slides, and Calendar through one self-hosted server. Search and organize files, create and edit Workspace content, manage sharing, and automate multi-step workflows while keeping control of the Google identity and credentials used for every call.

Why this server

  • Drive-first workflows: 130 tools cover file management, Shared Drives, permissions, revisions, rich Docs editing, Sheets formatting, Slides authoring, and Calendar events.
  • Local or hosted: use stdio for a personal desktop client, Streamable HTTP for a hosted integration, or OAuth-protected team mode for a shared service.
  • Identity control: local OAuth supports multiple Google accounts and per-tool account selection; service accounts and externally managed OAuth tokens are also supported.
  • Agent-friendly access: tools expose targeted operations, while the optional gdrive:/// resource interface supports direct reading and discovery.
  • Open and self-hosted: credentials and tokens stay in the environment you operate.

This project remains focused on deep Drive and editor workflows rather than attempting to expose every Google Workspace API.

Client compatibility

Compatibility is determined by the transport and authentication flow a client supports.

See Client configuration for configuration examples and transport requirements.

Quick start

1

Read from source at commit 9feabad12272OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add google-drive-mcp --env GOOGLE_DRIVE_OAUTH_CREDENTIALS=${GOOGLE_DRIVE_OAUTH_CREDENTIALS} -- npx -y @piotr-agier/[email protected]
03

Exposed tools (118)

54 read · 55 write · 9 destructive. Blast radius: 9 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
GOOGLE_DRIVE_OAUTH_CREDENTIALSreadPath to a Google OAuth 2.0 Desktop app credentials JSON file.
addCommentwriteAdd a comment quoting a text range, targeted by startIndex+endIndex or by textToFind. The comment appears in the document
addDataValidationwriteAdd data validation rules to a sheet range
addDocumentTabwriteAdd a new tab in a Google Doc
addGoogleSheetConditionalFormatwriteAdd conditional formatting to a Google Sheet
addNamedRangewriteCreate a named range
addPermissionwriteAdd a sharing permission to a file. If the principal already holds a permission on the file, Drive updates that permission instead of creating a second one, and the requested role is applied even when it is a downgrade (asking for
addSheetreadAlias for addSpreadsheetSheet (adds a new sheet/tab)
addSpreadsheetSheetreadAdds a new sheet/tab to an existing Google Spreadsheet
appendSpreadsheetRowsreadAppends rows of data to the end of a sheet in a Google Spreadsheet
applyTextStylewriteApply text formatting (bold, italic, color, etc.) to a range or found text. Use EITHER startIndex+endIndex OR textToFind for targeting.
authGetStatusreadShow authentication/token status and scope diagnostics
authListScopesreadList configured/requested scopes and currently granted scopes
authTestFileAccesswriteRun auth diagnostics against Drive API/file access
autoResizeColumnsreadAuto-size one or more columns to fit their content. Indices are 0-based and the interval is half-open [startColumn, endColumn) — to auto-fit a single column at position 5, pass startColumn: 5, endColumn: 6.
autoResizeRowsreadAuto-size one or more rows to fit their content. Indices are 0-based and the interval is half-open [startRow, endRow) — to auto-fit a single row at position 5, pass startRow: 5, endRow: 6.
bulkConvertFolderPdfsreadConvert all PDFs in a folder into Google Docs and return per-file results
convertPdfToGoogleDocreadConvert an existing PDF in Drive into an editable Google Doc
copyFilereadCreates a copy of a Google Drive file or document
createCalendarEventwriteCreate a new calendar event. Supports timed events, all-day events, and Google Meet integration.
createFolderwriteCreate a new folder in Google Drive
createFootnotewriteCreate a footnote in a Google Doc. Footnotes cannot be inserted inside equations, headers, footers, or other footnotes. For multi-tab docs, specify tabId to target a specific tab.
createGoogleDocwriteCreate a new Google Doc
createGoogleSheetwriteCreate a new Google Sheet. By default uses RAW mode which stores values as-is. Set valueInputOption to
createGoogleSlideswriteCreate a new Google Slides presentation
createGoogleSlidesShapewriteCreate a shape in Google Slides
createGoogleSlidesTextBoxwriteCreate a text box in Google Slides
createParagraphBulletsdestructiveAdd or remove bullet points / numbered lists on paragraphs in a Google Doc. Target paragraphs by startIndex+endIndex or textToFind. Use bulletPreset=
createShortcutwriteCreate a shortcut (link) to a file or folder in Google Drive. Useful for referencing the same document from multiple locations without duplicating it.
createTextFilewriteCreate a new text or markdown file
deleteCalendarEventdestructiveDelete a calendar event
deleteCommentdestructiveDelete a comment from the document
deleteGoogleSlidedestructiveDelete a slide from a presentation
deleteItemwriteMove a file or folder to trash (can be restored from Google Drive trash)
deleteRangedestructiveDelete content between start and end indices. Works on Google Docs and text/* files (e.g. text/plain, text/markdown). Index semantics differ by file type: Google Docs use the Docs API
deleteSheetdestructiveDelete a sheet/tab by sheetId
deleteSlideElementdestructiveDelete an element (image, text box, shape) from a Google Slides slide
downloadFilereadDownload a Google Drive file to a local path. For Google Workspace files (Docs, Sheets, Slides, Drawings), exports to the specified format. For regular files, downloads as-is. Streams directly to disk.
duplicateSlidereadDuplicate a slide in a presentation
editTableCellwriteEdit the content and/or style of a specific table cell. Requires knowing the table start index. For multi-tab docs, specify tabId to target a table in a specific tab.
exportSlideThumbnailreadExport a slide thumbnail URL
formatGoogleDocParagraphwriteApply paragraph formatting (alignment, indentation, spacing, heading style, borders, shading) in a Google Doc. Alias for applyParagraphStyle.
formatGoogleDocTextwriteApply text formatting (bold, italic, font, color, links, superscript/subscript) to a range or found text in a Google Doc. Alias for applyTextStyle.
formatGoogleSheetCellsreadFormat cells in a Google Sheet (background, borders, alignment)
formatGoogleSheetNumberswriteApply number formatting to cells in a Google Sheet
formatGoogleSheetTextwriteApply text formatting to cells in a Google Sheet
formatGoogleSlidesParagraphwriteApply paragraph formatting to text in Google Slides
formatGoogleSlidesTextwriteApply text formatting to elements in Google Slides
getCalendarEventreadGet a single calendar event by ID
getCalendarEventsreadGet events from a Google Calendar with optional filtering
getCommentreadGet a specific comment with its full thread of replies
getDocumentInforeadGets detailed information about a specific Google Document.
getGoogleDocContentreadGet content of a Google Doc with text indices for formatting
getGoogleDocContentPaginatedreadGet a portion of a Google Doc with text indices for formatting, with pagination support. Use offset and limit to read large documents in chunks.
getGoogleSheetContentreadGet content of a Google Sheet with cell information. Each row is returned as
getGoogleSlidesContentreadGet content of Google Slides with element IDs for formatting
getGoogleSlidesSpeakerNotesreadGet speaker notes from a specific slide in Google Slides
getRevisionsreadList revisions for a file
getSlideElementInforeadGet position, size, and transform of all elements on a slide. Returns actual rendered bounds.
getSpreadsheetInforeadGets detailed information about a Google Spreadsheet including all sheets/tabs
hideSheetDimensionreadHide a range of columns or rows in a sheet (sets hiddenByUser=true). Indices are 0-based and the interval is half-open [startIndex, endIndex) — to hide a single column/row at position 5, pass startIndex: 5, endIndex: 6.
insertImageFromUrlwriteInsert an inline image into a Google Document from a publicly accessible URL
insertLocalImagewriteUpload a local image file to Google Drive and insert it into a Google Document
insertSlidesImageFromUrlwriteInsert an image into a Google Slides slide from a publicly accessible URL
insertSlidesLocalImagewriteUpload a local image file to Google Drive and insert it into a Google Slides slide
insertSmartChipwriteInsert a person smart chip (mention) at a document index. Only person chips are supported by the Docs API; date and file chips are read-only.
insertTablewriteInsert a new table with the specified dimensions at a given index. For multi-tab docs, specify tabId to target a specific tab.
insertTextwriteInsert text at a specific index (surgical edit, doesn
listCalendarsreadList all accessible Google Calendars for the authenticated user
listCommentsreadList all comments in a Google Document
listDimensionGroupsreadList the row and column groups of a spreadsheet, with each group
listDocumentTabsreadList all tabs in a Google Doc with their IDs and hierarchy
listFolderreadList contents of a folder (defaults to root)
listGoogleDocsreadLists Google Documents from your Google Drive with optional filtering.
listGoogleSheetsreadLists Google Spreadsheets from your Google Drive with optional filtering
listPermissionsreadList sharing permissions for a file
listSharedDrivesreadList available Google Shared Drives
listSheetsreadList tabs/sheets in a Google Spreadsheet
lockFilereadLock a file to prevent editing by setting content restrictions. The file remains readable but cannot be modified until unlocked.
manage_accountsreadManage connected Google accounts. action=
mergeGoogleSheetCellswriteMerge cells in a Google Sheet
moveItemwriteMove a file or folder
moveSlideElementwriteMove and/or resize an element (image, text box, shape) on a Google Slides slide
protectRangereadProtect a range in a spreadsheet
readGoogleDocreadRead content of a Google Doc with format options. Supports multi-tab documents. Text/markdown output leads with the document
readGoogleDocPaginatedreadRead a portion of a Google Doc with pagination support. Use offset and limit to read large documents in chunks, avoiding output size limits.
readSmartChipsreadRead smart chip-like elements (person mentions, rich links, date chips) from the default tab of a document
readTextFilereadRead content of a text file (any text/* MIME type, e.g. text/plain, text/markdown, text/csv). For Google Docs, use readGoogleDoc.
removePermissiondestructiveRemove a permission from a file (by permissionId or emailAddress)
renameDocumentTabwriteRename an existing Google Doc tab
renameItemwriteRename a file or folder
renameSheetwriteRename a sheet/tab by sheetId
reorderSlidesreadReorder one or more slides in a presentation
replaceSlideImagewriteReplace an existing image in place, preserving its layering (z-order), position, size, and crop. Unlike delete+insert, which lands the new image on top of the stack, this keeps the image under any overlaid text.
replyToCommentwriteAdd a reply to an existing comment
restoreRevisionreadRestore a file to a selected revision (creates a new head revision). Note: workspace files (Docs, Sheets, Slides) are restored via export/import and may lose some formatting.
searchreadSearch for files in Google Drive. Results are sorted most-recently-modified first by default; use orderBy for a different order. Set rawQuery=true to pass a raw Google Drive API query supporting operators like modifiedTime, createdTime, mimeType, name contains, etc.
setColumnWidthwriteSet the width (in pixels) of one or more columns in a sheet. Indices are 0-based and the interval is half-open [startColumn, endColumn) — to resize a single column at position 5, pass startColumn: 5, endColumn: 6.
setElementTextdestructiveReplace the entire text of one shape/text box by objectId (element-scoped delete+insert in one atomic call). Unlike replaceAllTextInSlides, this cannot hit other slides, masters, or layouts, and does not depend on matching existing text. Pass empty text to clear the element.
setElementZOrderwriteChange the stacking order of page elements (updatePageElementsZOrder). Inserted images land on top of the stack and can cover overlay text — send them backward or to the back. All elements must be on the same page.
setGoogleSheetBorderswriteSet borders for cells in a Google Sheet
setGoogleSlidesBackgroundwriteSet background color for slides
setRowHeightwriteSet the height (in pixels) of one or more rows in a sheet. Indices are 0-based and the interval is half-open [startRow, endRow) — to resize a single row at position 5, pass startRow: 5, endRow: 6.
setSlideVisibilityreadShow or hide (skip) slides in one atomic call. Hidden slides are skipped in present mode and PDF export.
shareFilereadConvenience wrapper to share a file with a user email. If the user already holds a permission on the file, that permission
showSheetDimensionreadShow (unhide) a range of columns or rows in a sheet (sets hiddenByUser=false). Indices are 0-based and the interval is half-open [startIndex, endIndex) — to unhide a single column/row at position 5, pass startIndex: 5, endIndex: 6.
styleGoogleSlidesShapereadStyle shapes in Google Slides
unlockFilereadUnlock a previously locked file by removing content restrictions, restoring full edit access.
updateCalendarEventwriteUpdate an existing calendar event
updateDimensionGroupreadCollapse or expand an existing row or column group. Indices are 0-based and the interval is half-open [startIndex, endIndex). Use listDimensionGroups first to find the group
updateGoogleDocwriteUpdate an existing Google Doc (replaces all content). The replacement is one atomic batchUpdate, so a failure leaves the document unchanged rather than wiped. For multi-tab docs, specify tabId to replace a single tab
updateGoogleSheetwriteUpdate an existing Google Sheet. By default uses RAW mode which stores values as-is. Set valueInputOption to
updateGoogleSlideswriteUpdate an existing Google Slides presentation
updateGoogleSlidesSpeakerNoteswriteUpdate speaker notes for a specific slide in Google Slides
updatePermissionwriteUpdate an existing permission role
updateTextFilewriteUpdate an existing text or markdown file
uploadFilewriteUpload a file (any type: image, audio, video, PDF, etc.) to Google Drive, either from a local path on the server or from base64-encoded content. When fileId is provided, uploads the content as a new version of that existing file (in-place update) instead of creating a new file.
uploadPdfWithSplitwriteUpload PDF and optionally split into chunked parts (metadata split plan for now)
04

Trust audit

CAUTIONgrade B · trust 80/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (22)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/auth/client.ts:16
redirect_uris: (keys.redirect_uris as string[] | undefined) || ['http://127.0.0.1:3000/oauth2callback']
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
test/integration/cli-args.test.ts:144
const secret = 'TOPSECRET-client-secret-DO-NOT-LEAK-abcdef';
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
test/external-auth.test.ts:295
const PRIVATE_KEY = '-----BEGIN PRIVATE KEY-----\nsuper-secret-key-material\n-----END PRIVATE KEY-----\n';
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
createParagraphBullets, deleteCalendarEvent, deleteComment, deleteGoogleSlide, deleteRange, deleteSheet, deleteSlideElement, removePermission, setElementText
Why it matters. 9 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.cursorignore
.cursorignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/auth/team/clientFactory.ts:15
import { TimeoutError } from '../../utils/retry.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/auth/accountResolver.test.ts:6
import { AccountResolver, coversScopes } from '../../src/auth/accountResolver.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/auth/accountResolver.test.ts:7
import { AccountStore } from '../../src/auth/accountStore.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/auth/accountResolver.test.ts:8
import { SessionStore, STDIO_SESSION_ID } from '../../src/auth/sessionStore.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/auth/accountResolver.test.ts:9
import { AccountRecord } from '../../src/auth/types.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CHANGELOG.md:178
- **auth:** use loopback IP `127.0.0.1` instead of `localhost` for the OAuth callback redirect URI, matching the IPv4-only callback-server bind so the redirect resolves to the bound address on dual-st
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/authentication.md:51
The callback server binds to the loopback interface and the OAuth redirect URI uses the loopback IP — `http://127.0.0.1:<port>/oauth2callback` (default range `127.0.0.1:3000`–`127.0.0.1:3004`). **Desk
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/clients.md:85
"url": "http://127.0.0.1:3100/mcp"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/troubleshooting.md:24
4. **`redirect_uri_mismatch` (Web application clients only)**: The callback redirect URI uses the loopback IP `http://127.0.0.1:<port>/oauth2callback`. Switch to a "Desktop app" client (recommended), 
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/express, express, google-auth-library, googleapis, jszip, open, pdf-lib
Why it matters. 19 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:79
- **transport:** an HTTP client whose session has expired can now recover on its own instead of failing every call until the user reconnects by hand. The Streamable HTTP transport evicts a session aft
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:83
Stops a stalled OAuth token refresh from **hanging every call on the server**. The proactive refresh that runs five minutes before an access token expires awaited Google's token endpoint with no timeo
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:87
- **auth:** an OAuth token refresh that stalls no longer hangs every call on the server. The proactive refresh that runs five minutes before an access token expires awaited Google's token endpoint wit
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:106
- **team:** log lines now name the acting user. Team-mode dispatch, session lifecycle (created / idle timeout / closed), sign-in callback, and per-user tool logs carry the member's Google `sub` and em
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/authentication.md:237
With the Streamable HTTP transport in its default (single-user) mode, multiple MCP sessions sharing the same server process also share the same active default account. A `set_default` in one session i
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/deployment.md:131
When binding to `127.0.0.1` (default), DNS rebinding protection is automatically enabled. For remote deployments (`0.0.0.0`), prefer [Team Mode](#team-mode-multi-user-http-deployments), which authenti
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:13
- **Open and self-hosted:** credentials and tokens stay in the environment you operate.
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 9feabad12272full audit observations/trust-audit/mcp-server/piotr-agier__google-drive-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-069feabad12272CAUTIONB80first audit
06

Questions

What is the Google Drive MCP server?

A Model Context Protocol (MCP) server that provides secure integration with Google Drive, Docs, Sheets, Slides and Calendar. It allows Claude Desktop and other MCP clients to manage files in Google Drive through a standardized interface.

What tools does Google Drive expose?

118 in total: 54 read-only, 55 that write, and 9 that can delete or overwrite (createParagraphBullets, deleteCalendarEvent, deleteComment, deleteGoogleSlide, deleteRange). Every one is listed on this page with its risk.

Is Google Drive safe to connect to an agent?

With care. The audit graded it B (80/100) and found 22 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 9 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Google Drive need?

It reads GOOGLE_APPLICATION_CREDENTIALS, GOOGLE_CLIENT_SECRET_PATH, GOOGLE_DRIVE_MCP_ACCESS_TOKEN, GOOGLE_DRIVE_MCP_AUTH_PORT, GOOGLE_DRIVE_MCP_CLIENT_SECRET, GOOGLE_DRIVE_MCP_REFRESH_TOKEN, GOOGLE_DRIVE_MCP_TOKEN_PATH, GOOGLE_DRIVE_MCP_TOKEN_REFRESH_TIMEOUT, GOOGLE_DRIVE_OAUTH_CREDENTIALS and GOOGLE_TOKEN_PATH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Google Drive run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @piotr-agier/google-drive-mcp at 2.12.0.

How current is this page?

The grade is for one exact copy of the source (9feabad12272), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement