Atlas / MCP servers / taylorwilsdon / Google Workspace

Google WorkspaceBLOCK

mcp/taylorwilsdon/google-workspace-5

Control Gmail, Google Calendar, Docs, Sheets, Slides, Chat, Forms, Tasks, Search & Drive with AI - Comprehensive Google Workspace MCP Server & CLI Tool

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
—
Transport
stdio · streamable-http
License
MIT
Stars
3,205
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://opensource.org/licenses/MIT) [](https://www.python.org/downloads/) [](https://pypi.org/project/workspace-mcp/) [](https://pepy.tech/projects/workspace-mcp) [](https://mcptoplist.com/server/glama%2Ftaylorwilsdon%2Fgoogleworkspacemcp) [](https://workspacemcp.com/?utmsource=github.com&utmmedium=referral&utmcampaign=readme&utmcontent=badge-website)

Full natural language control over Google Calendar, Drive, Gmail, Docs, Sheets, Slides, Forms, Tasks, Contacts, and Chat through all MCP clients, AI assistants and developer tools. Includes a full featured CLI & Code Mode for use with tools like Claude Code and Codex!

The most feature-complete Google Workspace MCP server is in a class of it's own: it can do things that Google's own tooling and the built in integrations with Claude and ChatGPT can't come close to with multi-user support, rich fine-grained editing tools and the most extensive coverage of any Workspace AI integration in existence.

By leveraging native OAuth 2.1, stateless deployment capability and external auth server & gateway passthrough auth support, it's also the only Workspace MCP you can host for your whole organization centrally & securely!

Supports all fre

Read from source at commit 0e0dacede5abOBSERVED · 2026-09-22
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add workspace-mcp -- None workspace-mcp==1.28.0
03

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (22)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
core/utils.py:262
".netrc",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
core/utils.py:263
".git-credentials",
Why it matters. touches a credential store
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.oauth21
.env.oauth21
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
tests/gappsscript/manual_test.py:67
creds = pickle.load(token)
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/auth/test_port_resolver.py:46
return __import__(modname, fromlist=["*"])
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/auth/test_credential_security.py:84
path = cred_store._get_credential_path("../../etc/[email protected]")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/auth/test_gcs_credential_store.py:271
cred_store._blob_name("../../etc/[email protected]")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/core/test_extract_office_xml_text.py:226
relationships=[("rTraversal", "header", "../../etc/passwd")],
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/gmail/test_body_format.py:980
headers = _headers(Subject="../../etc/passwd")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/auth/test_gateway_identity.py:224
"http://127.0.0.1/jwks.json",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/auth/test_oauth_callback_server.py:68
"stdio", 9000, "http://127.0.0.1"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/auth/test_oauth_callback_server.py:78
assert replacement_server.base_uri == "http://127.0.0.1"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/core/test_allowed_redirect_uris.py:60
"http://localhost:*/callback,http://127.0.0.1:*/callback"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/core/test_allowed_redirect_uris.py:64
"http://127.0.0.1:*/callback",
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
tests/gmail/test_batch_modify_label_verification.py:206
service, message_ids=["msg-1", "msg-2"], add_label_ids=["TRASH"], verify=False
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
gdrive/drive_helpers.py:562
file_data = base64.b64decode(base64_content, validate=True)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
gmail/gmail_tools.py:1425
file_data = base64.b64decode(content_base64)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/core/test_pdf_image_utils.py:51
assert base64.b64decode(encoded_part) == raw
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/core/test_pdf_image_utils.py:59
assert base64.b64decode(encoded_part) == raw
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/gdrive/test_drive_file_content.py:217
assert base64.b64decode(b64_part) == image_bytes
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table

Gates applied: no_behavioural_pass.

Audited 2026-09-22 · audit v0.4.1 · source sha 0e0dacede5abfull audit observations/trust-audit/mcp-server/taylorwilsdon__google-workspace-5.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-220e0dacede5abBLOCKD69source changed, verdict held
2026-09-1801857793c7ceBLOCKD69first audit
05

Questions

What is the Google Workspace MCP server?

Control Gmail, Google Calendar, Docs, Sheets, Slides, Chat, Forms, Tasks, Search & Drive with AI - Comprehensive Google Workspace MCP Server & CLI Tool

Is Google Workspace safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Google Workspace need?

It reads EXTERNAL_OAUTH21_PROVIDER, FASTMCP_SERVER_AUTH_GOOGLE_JWT_SIGNING_KEY, GOOGLE_CLIENT_SECRETS, GOOGLE_CLIENT_SECRET_PATH, GOOGLE_MCP_CREDENTIALS_DIR, GOOGLE_OAUTH_CLIENT_ID, GOOGLE_OAUTH_CLIENT_SECRET, GOOGLE_OAUTH_REDIRECT_URI, GOOGLE_PSE_API_KEY, GOOGLE_SERVICE_ACCOUNT_KEY_FILE, GOOGLE_SERVICE_ACCOUNT_KEY_JSON and GOOGLE_TOKEN_PATH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Google Workspace run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as workspace-mcp.

How current is this page?

The grade is for one exact copy of the source (0e0dacede5ab), read on 2026-09-22. The repository is watched and re-audited when it changes.

Advertisement