Atlas / MCP servers / shinzo-labs / Gmail

GmailSAFE

mcp/shinzo-labs/gmail-9

MCP Implementation for Gmail Services

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
65 22r · 31w · 12d
Transport
stdio · streamable-http
License
MIT
Stars
61
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Gmail MCP Server

A Model Context Protocol (MCP) server implementation for the Gmail API, providing a standardized interface for email management, sending, and retrieval.

Features

  • Complete Gmail API coverage including messages, threads, labels, drafts, and settings
  • Support for sending, drafting, and managing emails
  • Label management with customizable colors and visibility settings
  • Thread operations for conversation management
  • Settings management including vacation responder, IMAP/POP, and language settings
  • History tracking for mailbox changes
  • Secure OAuth2 authentication using Google Cloud credentials

Prerequisites

Dependencies

For simplest installation, install Node.js 18+. If you would like to build locally, you will also need to install [pnpm](htt

Read from source at commit 2661f226a856OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add gmail-mcp --env AUTH_SERVER_PORT=${AUTH_SERVER_PORT} --env CLIENT_SECRET=${CLIENT_SECRET} --env REFRESH_TOKEN=${REFRESH_TOKEN} -- npx -y @shinzolabs/[email protected]
claude-desktop
{
  "mcpServers": {
    "gmail-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@shinzolabs/[email protected]"
      ],
      "env": {
        "AUTH_SERVER_PORT": "${AUTH_SERVER_PORT}",
        "CLIENT_SECRET": "${CLIENT_SECRET}",
        "REFRESH_TOKEN": "${REFRESH_TOKEN}"
      }
    }
  }
}
03

Exposed tools (65)

22 read · 31 write · 12 destructive. Blast radius: 12 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_delegatewriteAdds a delegate to the specified account
batch_delete_messagesdestructiveDelete multiple messages
batch_modify_messageswriteModify the labels on multiple messages
create_draftwriteCreate a draft email in Gmail. Note the mechanics of the raw parameter.
create_filterwriteCreates a filter
create_forwarding_addresswriteCreates a forwarding address
create_labelwriteCreate a new label
create_send_aswriteCreates a custom send-as alias
delete_draftdestructiveDelete a draft
delete_filterdestructiveDeletes a filter
delete_forwarding_addressdestructiveDeletes the specified forwarding address
delete_labeldestructiveDelete a label
delete_messagedestructiveImmediately and permanently delete a message
delete_send_asdestructiveDeletes the specified send-as alias
delete_smime_infodestructiveDeletes the specified S/MIME config for the specified send-as alias
delete_threaddestructiveDelete a thread
get_attachmentreadGet a message attachment
get_auto_forwardingreadGets auto-forwarding settings
get_delegatereadGets the specified delegate
get_draftreadGet a specific draft by ID
get_filterreadGets a filter
get_forwarding_addressreadGets the specified forwarding address
get_imapreadGets IMAP settings
get_labelreadGet a specific label by ID
get_languagereadGets language settings
get_messagereadGet a specific message by ID with format options
get_popreadGets POP settings
get_profilereadGet the current user
get_send_aswriteGets the specified send-as alias
get_smime_infowriteGets the specified S/MIME config for the specified send-as alias
get_threadreadGet a specific thread by ID
get_vacationreadGet vacation responder settings
insert_smime_infowriteInsert (upload) the given S/MIME config for the specified send-as alias
list_delegatesreadLists the delegates for the specified account
list_draftsreadList drafts in the user
list_filtersreadLists the message filters of a Gmail user
list_forwarding_addressesreadLists the forwarding addresses for the specified account
list_labelsreadList all labels in the user
list_messagesreadList messages in the user
list_send_aswriteLists the send-as aliases for the specified account
list_smime_infowriteLists S/MIME configs for the specified send-as alias
list_threadsreadList threads in the user
modify_messagewriteModify the labels on a message
modify_threadwriteModify the labels applied to a thread
patch_labelwritePatch an existing label (partial update)
patch_send_aswritePatches the specified send-as alias
remove_delegatedestructiveRemoves the specified delegate
send_draftwriteSend an existing draft
send_messagewriteSend an email message to specified recipients. Note the mechanics of the raw parameter.
set_default_smime_infowriteSets the default S/MIME config for the specified send-as alias
stop_mail_watchwriteStop receiving push notifications for the given user mailbox
trash_messagewriteMove a message to the trash
trash_threadwriteMove a thread to the trash
untrash_messagedestructiveRemove a message from the trash
untrash_threaddestructiveRemove a thread from the trash
update_auto_forwardingwriteUpdates automatic forwarding settings
update_draftwrite
update_imapwriteUpdates IMAP settings
update_labelwriteUpdate an existing label
update_languagewriteUpdates language settings
update_popwriteUpdates POP settings
update_send_aswriteUpdates a send-as alias
update_vacationwriteUpdate vacation responder settings
verify_send_aswriteSends a verification email to the specified send-as alias
watch_mailboxreadWatch for changes to the user
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
batch_delete_messages, delete_draft, delete_filter, delete_forwarding_address, delete_label, delete_message, delete_send_as, delete_smime_info, delete_thread, remove_delegate, untrash_message, untrash
Why it matters. 12 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@shinzolabs/instrumentation-mcp
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 2661f226a856full audit observations/trust-audit/mcp-server/shinzo-labs__gmail-9.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-082661f226a856SAFEB89first audit
06

Questions

What is the Gmail MCP server?

MCP Implementation for Gmail Services

What tools does Gmail expose?

65 in total: 22 read-only, 31 that write, and 12 that can delete or overwrite (batch_delete_messages, delete_draft, delete_filter, delete_forwarding_address, delete_label). Every one is listed on this page with its risk.

Is Gmail safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 12 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Gmail need?

It reads AUTH_SERVER_PORT, CLIENT_SECRET and REFRESH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Gmail run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @shinzolabs/gmail-mcp at 1.7.4.

How current is this page?

The grade is for one exact copy of the source (2661f226a856), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement