Personal Assistant AgentSAFE
A personal assistant AI agent built with the Model Context Protocol (MCP)
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A versatile personal assistant AI agent built with the Model Context Protocol (MCP) that helps with calendar, tasks, emails, and more.
Overview
This project is a Model Context Protocol (MCP) server that provides a set of tools for a personal assistant agent. It can be integrated with MCP clients like Claude for Desktop to give AI assistants the ability to:
- Manage calendar events
- Track tasks and to-dos
- Read and send emails
- Search the web and retrieve information
- Control smart home devices
Requirements
⚠️ IMPORTANT: Python 3.10 or higher is required for the MCP SDK. The server will not work with earlier Python versions.
- Python 3.10+
- MCP SDK 1.2.0+
- Required Python packages (see requirements.txt)
Installation
- Clone the repository:
git clone https://github.com/yourusername/mcp-pa-ai-agent.git cd mcp-pa-ai-agent
- Ensure you have Python 3.10+:
python --version
- If your system Python is older than 3.10, set up a compatible environment:
# Using conda conda create -n mcp-env python=3.10 conda activate mcp-env # OR using venv (if Python 3.10+ is installed elsewhere) python3.10 -m venv venv source venv/bin/activate # On Windows: venv\Scripts\activate
- Install dependencies:
pip install -r requirements.txt
- Configure environment variables by copying the example file:
cp .env.example .env
- Edit the
.envfile with your API credentials and settings.
Running the Server
Start the MCP server with:
python mcp_server.py
The server will start and listen for MCP client connections.
Connecting to Claude for Desktop
- Install Claude for Desktop
- Configure Claude for Desktop to use this MCP server by editing the configuration file at:
- MacOS/Linux:
~/Library/Application Support/Claude/claude_desktop_config.json - Windows:
%APPDATA%\Claude\claude_desktop_config.json
- Add the
fec8e044b3cfOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-pa-ai-agent --env DUCKDUCKGO_API_KEY=${DUCKDUCKGO_API_KEY} --env GOOGLE_ACCESS_TOKEN=${GOOGLE_ACCESS_TOKEN} --env GOOGLE_CLIENT_SECRET=${GOOGLE_CLIENT_SECRET} --env GOOGLE_REFRESH_TOKEN=${GOOGLE_REFRESH_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"mcp-pa-ai-agent": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"DUCKDUCKGO_API_KEY": "${DUCKDUCKGO_API_KEY}",
"GOOGLE_ACCESS_TOKEN": "${GOOGLE_ACCESS_TOKEN}",
"GOOGLE_CLIENT_SECRET": "${GOOGLE_CLIENT_SECRET}",
"GOOGLE_REFRESH_TOKEN": "${GOOGLE_REFRESH_TOKEN}"
}
}
}
}Exposed tools (19)
12 read · 6 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_task | write | Add a new task. |
control_device | read | Control a smart home device. |
create_chart | write | Create a chart from data points. |
create_event | write | Create a new calendar event. |
create_scene | write | Create a new scene with defined device states. |
delete_task | destructive | Delete a task. |
get_device_state | read | Get the current state of a smart home device. |
get_emails | read | Get recent emails from a specific label. |
get_events | read | Get upcoming calendar events. |
get_free_time | read | Find free time slots in your calendar for a specific date. |
get_news | read | Get latest news, optionally filtered by topic. |
get_weather | read | Get current weather information for a location. |
list_devices | read | List all available smart home devices. |
list_tasks | read | List tasks with optional filtering by status. |
read_email | read | Read the full content of a specific email. |
search_emails | read | Search emails using Gmail search syntax. |
send_email | write | Send an email. |
update_task_status | write | Update the status of a task. |
web_search | read | Search the web for information. |
Trust audit
SAFEgrade B · trust 86/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (12)
delete_task
import config from '../../config/index.js';
import logger from '../../utils/logger.js';
import logger from '../../../utils/logger.js';
import config from '../../../config/index.js';
import logger from '../../utils/logger.js';
@anthropic-ai/mcp-server, dotenv, express, googleapis, ioredis, node-cron, node-fetch, nodemailer
mcp, httpx, python-dotenv, google-api-python-client, google-auth-oauthlib, redis, python-crontab
For more control, you can use the low-level server implementation directly. This gives you full access to the protocol and allows you to customize every aspect of your server, including lifecycle mana
load_dotenv() # load environment variables from .env
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass, no_license.
fec8e044b3cffull audit observations/trust-audit/mcp-server/zhangzhongnan928__personal-assistant-agent.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | fec8e044b3cf | SAFE | B | 86 | first audit |
Questions
What is the Personal Assistant Agent MCP server?
A personal assistant AI agent built with the Model Context Protocol (MCP)
What tools does Personal Assistant Agent expose?
19 in total: 12 read-only, 6 that write, and 1 that can delete or overwrite (delete_task). Every one is listed on this page with its risk.
Is Personal Assistant Agent safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (86/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Personal Assistant Agent need?
It reads DUCKDUCKGO_API_KEY, GOOGLE_ACCESS_TOKEN, GOOGLE_CLIENT_SECRET, GOOGLE_REFRESH_TOKEN, HOME_ASSISTANT_TOKEN, NEWS_API_KEY, REDIS_PASSWORD and WEATHER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Personal Assistant Agent run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-pa-ai-agent at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (fec8e044b3cf), read on 2026-10-09. The repository is watched and re-audited when it changes.