Atlas / MCP servers / taylorwilsdon / google_workspace_mcp

google_workspace_mcpBLOCK

mcp/taylorwilsdon/google-workspace-mcp

Control Gmail, Google Calendar, Docs, Sheets, Slides, Chat, Forms, Tasks, Search & Drive with AI - Comprehensive Google Workspace MCP Server & CLI Tool

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
—
Transport
stdio · streamable-http
License
MIT
Stars
3,288
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://opensource.org/licenses/MIT) [](https://www.python.org/downloads/) [](https://pypi.org/project/workspace-mcp/) [](https://pepy.tech/projects/workspace-mcp) [](https://mcptoplist.com/server/glama%2Ftaylorwilsdon%2Fgoogleworkspacemcp) [](https://workspacemcp.com/?utmsource=github.com&utmmedium=referral&utmcampaign=readme&utmcontent=badge-website)

Full natural language control over Google Calendar, Drive, Gmail, Docs, Sheets, Slides, Forms, Tasks, Contacts, and Chat through all MCP clients, AI assistants and developer tools. Includes a full featured CLI & Code Mode for use with tools like Claude Code and Codex!

The most feature-complete Google Workspace MCP server is in a class of it's own: it can do things that Google's own tooling and the built in integrations with Claude and ChatGPT can't come close to with multi-user support, rich fine-grained editing tools and the most extensive coverage of any Workspace AI integration in existence.

By leveraging native OAuth 2.1, stateless deployment capability and external auth server & gateway passthrough auth support, it's also the only Workspace MCP you can host for your whole organization centrally & securely!

Supports all fre

Read from source at commit 1a725d4493adOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add workspace-mcp -- None workspace-mcp==2.0.1
03

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (23)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
core/utils.py:360
".netrc",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
core/utils.py:361
".git-credentials",
Why it matters. touches a credential store
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_valkey_storage.py:27
PASSWORD = "hunter2-valkey-password"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.oauth21
.env.oauth21
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
tests/gappsscript/manual_test.py:67
creds = pickle.load(token)
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/auth/test_port_resolver.py:46
return importlib.reload(importlib.import_module(modname))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/auth/test_credential_security.py:84
path = cred_store._get_credential_path("../../etc/[email protected]")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/auth/test_gcs_credential_store.py:271
cred_store._blob_name("../../etc/[email protected]")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/core/test_extract_office_xml_text.py:226
relationships=[("rTraversal", "header", "../../etc/passwd")],
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/gmail/test_body_format.py:1034
headers = _headers(Subject="../../etc/passwd")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/auth/test_gateway_identity.py:224
"http://127.0.0.1/jwks.json",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/auth/test_oauth_callback_server.py:68
"stdio", 9000, "http://127.0.0.1"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/auth/test_oauth_callback_server.py:78
assert replacement_server.base_uri == "http://127.0.0.1"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/core/test_allowed_redirect_uris.py:60
"http://localhost:*/callback,http://127.0.0.1:*/callback"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/core/test_allowed_redirect_uris.py:64
"http://127.0.0.1:*/callback",
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
tests/gmail/test_batch_modify_label_verification.py:206
service, message_ids=["msg-1", "msg-2"], add_label_ids=["TRASH"], verify=False
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
gdrive/drive_helpers.py:740
file_data = base64.b64decode(base64_content, validate=True)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
gmail/gmail_tools.py:1435
file_data = base64.b64decode(content_base64)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/core/test_pdf_image_utils.py:51
assert base64.b64decode(encoded_part) == raw
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/core/test_pdf_image_utils.py:59
assert base64.b64decode(encoded_part) == raw
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/gdrive/test_drive_download_streaming.py:244
assert base64.b64decode(resource.resource.blob) == payload
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 1a725d4493adfull audit observations/trust-audit/mcp-server/taylorwilsdon__google_workspace_mcp.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-061a725d4493adBLOCKD69first audit
05

Questions

What is the google_workspace_mcp MCP server?

Control Gmail, Google Calendar, Docs, Sheets, Slides, Chat, Forms, Tasks, Search & Drive with AI - Comprehensive Google Workspace MCP Server & CLI Tool

Is google_workspace_mcp safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does google_workspace_mcp need?

It reads EXTERNAL_OAUTH21_PROVIDER, FASTMCP_SERVER_AUTH_GOOGLE_JWT_SIGNING_KEY, GOOGLE_CLIENT_SECRETS, GOOGLE_CLIENT_SECRET_PATH, GOOGLE_MCP_CREDENTIALS_DIR, GOOGLE_OAUTH_CLIENT_ID, GOOGLE_OAUTH_CLIENT_SECRET, GOOGLE_OAUTH_REDIRECT_URI, GOOGLE_PSE_API_KEY, GOOGLE_SERVICE_ACCOUNT_KEY_FILE, GOOGLE_SERVICE_ACCOUNT_KEY_JSON and GOOGLE_TOKEN_PATH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does google_workspace_mcp run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as workspace-mcp.

How current is this page?

The grade is for one exact copy of the source (1a725d4493ad), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement