GmailSAFE
MCP Implementation for Gmail Services
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Gmail MCP Server
A Model Context Protocol (MCP) server implementation for the Gmail API, providing a standardized interface for email management, sending, and retrieval.
Features
- Complete Gmail API coverage including messages, threads, labels, drafts, and settings
- Support for sending, drafting, and managing emails
- Label management with customizable colors and visibility settings
- Thread operations for conversation management
- Settings management including vacation responder, IMAP/POP, and language settings
- History tracking for mailbox changes
- Secure OAuth2 authentication using Google Cloud credentials
Prerequisites
Dependencies
For simplest installation, install Node.js 18+. If you would like to build locally, you will also need to install [pnpm](htt
2661f226a856OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add gmail-mcp --env AUTH_SERVER_PORT=${AUTH_SERVER_PORT} --env CLIENT_SECRET=${CLIENT_SECRET} --env REFRESH_TOKEN=${REFRESH_TOKEN} -- npx -y @shinzolabs/[email protected]{
"mcpServers": {
"gmail-mcp": {
"command": "npx",
"args": [
"-y",
"@shinzolabs/[email protected]"
],
"env": {
"AUTH_SERVER_PORT": "${AUTH_SERVER_PORT}",
"CLIENT_SECRET": "${CLIENT_SECRET}",
"REFRESH_TOKEN": "${REFRESH_TOKEN}"
}
}
}
}Exposed tools (65)
22 read · 31 write · 12 destructive. Blast radius: 12 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_delegate | write | Adds a delegate to the specified account |
batch_delete_messages | destructive | Delete multiple messages |
batch_modify_messages | write | Modify the labels on multiple messages |
create_draft | write | Create a draft email in Gmail. Note the mechanics of the raw parameter. |
create_filter | write | Creates a filter |
create_forwarding_address | write | Creates a forwarding address |
create_label | write | Create a new label |
create_send_as | write | Creates a custom send-as alias |
delete_draft | destructive | Delete a draft |
delete_filter | destructive | Deletes a filter |
delete_forwarding_address | destructive | Deletes the specified forwarding address |
delete_label | destructive | Delete a label |
delete_message | destructive | Immediately and permanently delete a message |
delete_send_as | destructive | Deletes the specified send-as alias |
delete_smime_info | destructive | Deletes the specified S/MIME config for the specified send-as alias |
delete_thread | destructive | Delete a thread |
get_attachment | read | Get a message attachment |
get_auto_forwarding | read | Gets auto-forwarding settings |
get_delegate | read | Gets the specified delegate |
get_draft | read | Get a specific draft by ID |
get_filter | read | Gets a filter |
get_forwarding_address | read | Gets the specified forwarding address |
get_imap | read | Gets IMAP settings |
get_label | read | Get a specific label by ID |
get_language | read | Gets language settings |
get_message | read | Get a specific message by ID with format options |
get_pop | read | Gets POP settings |
get_profile | read | Get the current user |
get_send_as | write | Gets the specified send-as alias |
get_smime_info | write | Gets the specified S/MIME config for the specified send-as alias |
get_thread | read | Get a specific thread by ID |
get_vacation | read | Get vacation responder settings |
insert_smime_info | write | Insert (upload) the given S/MIME config for the specified send-as alias |
list_delegates | read | Lists the delegates for the specified account |
list_drafts | read | List drafts in the user |
list_filters | read | Lists the message filters of a Gmail user |
list_forwarding_addresses | read | Lists the forwarding addresses for the specified account |
list_labels | read | List all labels in the user |
list_messages | read | List messages in the user |
list_send_as | write | Lists the send-as aliases for the specified account |
list_smime_info | write | Lists S/MIME configs for the specified send-as alias |
list_threads | read | List threads in the user |
modify_message | write | Modify the labels on a message |
modify_thread | write | Modify the labels applied to a thread |
patch_label | write | Patch an existing label (partial update) |
patch_send_as | write | Patches the specified send-as alias |
remove_delegate | destructive | Removes the specified delegate |
send_draft | write | Send an existing draft |
send_message | write | Send an email message to specified recipients. Note the mechanics of the raw parameter. |
set_default_smime_info | write | Sets the default S/MIME config for the specified send-as alias |
stop_mail_watch | write | Stop receiving push notifications for the given user mailbox |
trash_message | write | Move a message to the trash |
trash_thread | write | Move a thread to the trash |
untrash_message | destructive | Remove a message from the trash |
untrash_thread | destructive | Remove a thread from the trash |
update_auto_forwarding | write | Updates automatic forwarding settings |
update_draft | write | |
update_imap | write | Updates IMAP settings |
update_label | write | Update an existing label |
update_language | write | Updates language settings |
update_pop | write | Updates POP settings |
update_send_as | write | Updates a send-as alias |
update_vacation | write | Update vacation responder settings |
verify_send_as | write | Sends a verification email to the specified send-as alias |
watch_mailbox | read | Watch for changes to the user |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
batch_delete_messages, delete_draft, delete_filter, delete_forwarding_address, delete_label, delete_message, delete_send_as, delete_smime_info, delete_thread, remove_delegate, untrash_message, untrash
@shinzolabs/instrumentation-mcp
Gates applied: no_behavioural_pass.
2661f226a856full audit observations/trust-audit/mcp-server/shinzo-labs__gmail-9.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 2661f226a856 | SAFE | B | 89 | first audit |
Questions
What is the Gmail MCP server?
MCP Implementation for Gmail Services
What tools does Gmail expose?
65 in total: 22 read-only, 31 that write, and 12 that can delete or overwrite (batch_delete_messages, delete_draft, delete_filter, delete_forwarding_address, delete_label). Every one is listed on this page with its risk.
Is Gmail safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 12 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Gmail need?
It reads AUTH_SERVER_PORT, CLIENT_SECRET and REFRESH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Gmail run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @shinzolabs/gmail-mcp at 1.7.4.
How current is this page?
The grade is for one exact copy of the source (2661f226a856), read on 2026-10-08. The repository is watched and re-audited when it changes.