Google WorkspaceBLOCK
Control Gmail, Google Calendar, Docs, Sheets, Slides, Chat, Forms, Tasks, Search & Drive with AI - Comprehensive Google Workspace MCP Server & CLI Tool
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://opensource.org/licenses/MIT) [](https://www.python.org/downloads/) [](https://pypi.org/project/workspace-mcp/) [](https://pepy.tech/projects/workspace-mcp) [](https://mcptoplist.com/server/glama%2Ftaylorwilsdon%2Fgoogleworkspacemcp) [](https://workspacemcp.com/?utmsource=github.com&utmmedium=referral&utmcampaign=readme&utmcontent=badge-website)
Full natural language control over Google Calendar, Drive, Gmail, Docs, Sheets, Slides, Forms, Tasks, Contacts, and Chat through all MCP clients, AI assistants and developer tools. Includes a full featured CLI & Code Mode for use with tools like Claude Code and Codex!
The most feature-complete Google Workspace MCP server is in a class of it's own: it can do things that Google's own tooling and the built in integrations with Claude and ChatGPT can't come close to with multi-user support, rich fine-grained editing tools and the most extensive coverage of any Workspace AI integration in existence.
By leveraging native OAuth 2.1, stateless deployment capability and external auth server & gateway passthrough auth support, it's also the only Workspace MCP you can host for your whole organization centrally & securely!
Supports all fre
0e0dacede5abOBSERVED · 2026-09-22Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add workspace-mcp -- None workspace-mcp==1.28.0
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (22)
".netrc",
".git-credentials",
.env.oauth21
.mcpbignore
creds = pickle.load(token)
return __import__(modname, fromlist=["*"])
path = cred_store._get_credential_path("../../etc/[email protected]")cred_store._blob_name("../../etc/[email protected]")relationships=[("rTraversal", "header", "../../etc/passwd")],headers = _headers(Subject="../../etc/passwd")
"http://127.0.0.1/jwks.json",
"stdio", 9000, "http://127.0.0.1"
assert replacement_server.base_uri == "http://127.0.0.1"
"http://localhost:*/callback,http://127.0.0.1:*/callback"
"http://127.0.0.1:*/callback",
service, message_ids=["msg-1", "msg-2"], add_label_ids=["TRASH"], verify=False
file_data = base64.b64decode(base64_content, validate=True)
file_data = base64.b64decode(content_base64)
assert base64.b64decode(encoded_part) == raw
assert base64.b64decode(encoded_part) == raw
assert base64.b64decode(b64_part) == image_bytes
Gates applied: no_behavioural_pass.
0e0dacede5abfull audit observations/trust-audit/mcp-server/taylorwilsdon__google-workspace-5.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-22 | 0e0dacede5ab | BLOCK | D | 69 | source changed, verdict held |
| 2026-09-18 | 01857793c7ce | BLOCK | D | 69 | first audit |
Questions
What is the Google Workspace MCP server?
Control Gmail, Google Calendar, Docs, Sheets, Slides, Chat, Forms, Tasks, Search & Drive with AI - Comprehensive Google Workspace MCP Server & CLI Tool
Is Google Workspace safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Google Workspace need?
It reads EXTERNAL_OAUTH21_PROVIDER, FASTMCP_SERVER_AUTH_GOOGLE_JWT_SIGNING_KEY, GOOGLE_CLIENT_SECRETS, GOOGLE_CLIENT_SECRET_PATH, GOOGLE_MCP_CREDENTIALS_DIR, GOOGLE_OAUTH_CLIENT_ID, GOOGLE_OAUTH_CLIENT_SECRET, GOOGLE_OAUTH_REDIRECT_URI, GOOGLE_PSE_API_KEY, GOOGLE_SERVICE_ACCOUNT_KEY_FILE, GOOGLE_SERVICE_ACCOUNT_KEY_JSON and GOOGLE_TOKEN_PATH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Google Workspace run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as workspace-mcp.
How current is this page?
The grade is for one exact copy of the source (0e0dacede5ab), read on 2026-09-22. The repository is watched and re-audited when it changes.