Atlas / MCP servers / tanaikech / Workspace Automation Suite

Workspace Automation SuiteSAFE

mcp/tanaikech/workspace-automation-suite

The Gemini CLI confirmed that the MCP server built with Google Apps Script (GAS), a low-code platform, offers immense possibilities. If you've created snippets for GAS, these could be revitalized and/or leveraged in new ways by using them as the MCP server. The Gemini CLI and other MCP clients will

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
6 6r · 0w · 0d
Transport
—
License
MIT
Stars
106
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/tanaikech-toolsformcpserver)

Now, ToolsForMCPServer can be used as a Gemini extension. You can see how to install it at https://github.com/tanaikech/ToolsForMCPServer-extension.

The Gemini CLI confirmed that the MCP server built with Google Apps Script (GAS), a low-code platform, offers immense possibilities. If you've created snippets for GAS, these could be revitalized and/or leveraged in new ways by using them as the MCP server. The Gemini CLI and other MCP clients will be useful in achieving this.

[](LICENCE)

Abstract

The Gemini CLI provides a powerful command-line interface for interacting with Google's Gemini models. By leveraging the Model Context Protocol (MCP), the CLI can be extended with custom tools. This report explores the integration of the Gemini CLI with an MCP server built using Google Apps Script Web Apps. We demonstrate how this combination simplifies authorization for Google Workspace APIs (Gmail, Drive, Calendar, etc.), allowing Gemini to execute complex, multi-step tasks directly within the Google ecosystem. We provide setup instructions and several practical examples showcasing how this integration unlocks significant potential for automation and productivity enhancement.

Introduction

Recently, I published a report titled "Gemini CLI with MCP Server Built by Web Apps of Google Apps Script" (Ref). This initial report highlighted how a Model Context Protocol (MCP) server, developed using Google Apps Script Web Apps, can be in

Read from source at commit 55800939ce90OBSERVED · 2026-10-07
02

Exposed tools (6)

6 read · 0 write · 0 destructive.

ToolRiskDescription
filenamereadFilename of the search file.
generate_roadmapreadGenerate a roadmap in Google Sheets.
get_weatherreadSearch the current weather.
goalreadGoal of the roadmap.
locationreadLocation of the weather.
search_files_on_google_drivereadSearch files on Google Drive.
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (3)

LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:777
- Following [this report](https://medium.com/google-cloud/generating-request-body-for-apis-using-gemini-43977961ca2a), the request body is now generated on the MCP server side. Therefore, when using t
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
images/fig1.jpg
images/fig1.jpg
Why it matters. 1440467 bytes not read
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:340
Have you ever faced a task that isn’t part of your routine but is tedious to do manually, like, ‘I need to add a “[For Review]” prefix to the titles of all Google Docs in a specific folder this aftern

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 55800939ce90full audit observations/trust-audit/mcp-server/tanaikech__workspace-automation-suite.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0755800939ce90SAFEB89first audit
05

Questions

What is the Workspace Automation Suite MCP server?

The Gemini CLI confirmed that the MCP server built with Google Apps Script (GAS), a low-code platform, offers immense possibilities. If you've created snippets for GAS, these could be revitalized and/or leveraged in new ways by using them as the MCP server. The Gemini CLI and other MCP clients will

What tools does Workspace Automation Suite expose?

6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Workspace Automation Suite safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Workspace Automation Suite need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (55800939ce90), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement