google_workspace_mcpBLOCK
Control Gmail, Google Calendar, Docs, Sheets, Slides, Chat, Forms, Tasks, Search & Drive with AI - Comprehensive Google Workspace MCP Server & CLI Tool
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://opensource.org/licenses/MIT) [](https://www.python.org/downloads/) [](https://pypi.org/project/workspace-mcp/) [](https://pepy.tech/projects/workspace-mcp) [](https://mcptoplist.com/server/glama%2Ftaylorwilsdon%2Fgoogleworkspacemcp) [](https://workspacemcp.com/?utmsource=github.com&utmmedium=referral&utmcampaign=readme&utmcontent=badge-website)
Full natural language control over Google Calendar, Drive, Gmail, Docs, Sheets, Slides, Forms, Tasks, Contacts, and Chat through all MCP clients, AI assistants and developer tools. Includes a full featured CLI & Code Mode for use with tools like Claude Code and Codex!
The most feature-complete Google Workspace MCP server is in a class of it's own: it can do things that Google's own tooling and the built in integrations with Claude and ChatGPT can't come close to with multi-user support, rich fine-grained editing tools and the most extensive coverage of any Workspace AI integration in existence.
By leveraging native OAuth 2.1, stateless deployment capability and external auth server & gateway passthrough auth support, it's also the only Workspace MCP you can host for your whole organization centrally & securely!
Supports all fre
1a725d4493adOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add workspace-mcp -- None workspace-mcp==2.0.1
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (23)
".netrc",
".git-credentials",
PASSWORD = "hunter2-valkey-password"
.env.oauth21
.mcpbignore
creds = pickle.load(token)
return importlib.reload(importlib.import_module(modname))
path = cred_store._get_credential_path("../../etc/[email protected]")cred_store._blob_name("../../etc/[email protected]")relationships=[("rTraversal", "header", "../../etc/passwd")],headers = _headers(Subject="../../etc/passwd")
"http://127.0.0.1/jwks.json",
"stdio", 9000, "http://127.0.0.1"
assert replacement_server.base_uri == "http://127.0.0.1"
"http://localhost:*/callback,http://127.0.0.1:*/callback"
"http://127.0.0.1:*/callback",
service, message_ids=["msg-1", "msg-2"], add_label_ids=["TRASH"], verify=False
file_data = base64.b64decode(base64_content, validate=True)
file_data = base64.b64decode(content_base64)
assert base64.b64decode(encoded_part) == raw
assert base64.b64decode(encoded_part) == raw
assert base64.b64decode(resource.resource.blob) == payload
Gates applied: no_behavioural_pass.
1a725d4493adfull audit observations/trust-audit/mcp-server/taylorwilsdon__google_workspace_mcp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 1a725d4493ad | BLOCK | D | 69 | first audit |
Questions
What is the google_workspace_mcp MCP server?
Control Gmail, Google Calendar, Docs, Sheets, Slides, Chat, Forms, Tasks, Search & Drive with AI - Comprehensive Google Workspace MCP Server & CLI Tool
Is google_workspace_mcp safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does google_workspace_mcp need?
It reads EXTERNAL_OAUTH21_PROVIDER, FASTMCP_SERVER_AUTH_GOOGLE_JWT_SIGNING_KEY, GOOGLE_CLIENT_SECRETS, GOOGLE_CLIENT_SECRET_PATH, GOOGLE_MCP_CREDENTIALS_DIR, GOOGLE_OAUTH_CLIENT_ID, GOOGLE_OAUTH_CLIENT_SECRET, GOOGLE_OAUTH_REDIRECT_URI, GOOGLE_PSE_API_KEY, GOOGLE_SERVICE_ACCOUNT_KEY_FILE, GOOGLE_SERVICE_ACCOUNT_KEY_JSON and GOOGLE_TOKEN_PATH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does google_workspace_mcp run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as workspace-mcp.
How current is this page?
The grade is for one exact copy of the source (1a725d4493ad), read on 2026-10-06. The repository is watched and re-audited when it changes.