Atlas / MCP servers / zhangzhongnan928 / Personal Assistant Agent

Personal Assistant AgentSAFE

mcp/zhangzhongnan928/personal-assistant-agent

A personal assistant AI agent built with the Model Context Protocol (MCP)

Verdict
SAFE
Grade
B
Trust score
86 /100
Exposed tools
19 12r · 6w · 1d
Transport
stdio
License
—
Stars
23
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A versatile personal assistant AI agent built with the Model Context Protocol (MCP) that helps with calendar, tasks, emails, and more.

Overview

This project is a Model Context Protocol (MCP) server that provides a set of tools for a personal assistant agent. It can be integrated with MCP clients like Claude for Desktop to give AI assistants the ability to:

  • Manage calendar events
  • Track tasks and to-dos
  • Read and send emails
  • Search the web and retrieve information
  • Control smart home devices

Requirements

⚠️ IMPORTANT: Python 3.10 or higher is required for the MCP SDK. The server will not work with earlier Python versions.

  • Python 3.10+
  • MCP SDK 1.2.0+
  • Required Python packages (see requirements.txt)

Installation

  1. Clone the repository:
git clone https://github.com/yourusername/mcp-pa-ai-agent.git
cd mcp-pa-ai-agent
  1. Ensure you have Python 3.10+:
python --version
  1. If your system Python is older than 3.10, set up a compatible environment:
# Using conda
conda create -n mcp-env python=3.10
conda activate mcp-env

# OR using venv (if Python 3.10+ is installed elsewhere)
python3.10 -m venv venv
source venv/bin/activate  # On Windows: venv\Scripts\activate
  1. Install dependencies:
pip install -r requirements.txt
  1. Configure environment variables by copying the example file:
cp .env.example .env
  1. Edit the .env file with your API credentials and settings.

Running the Server

Start the MCP server with:

python mcp_server.py

The server will start and listen for MCP client connections.

Connecting to Claude for Desktop

  1. Install Claude for Desktop
  1. Configure Claude for Desktop to use this MCP server by editing the configuration file at:
  2. MacOS/Linux: ~/Library/Application Support/Claude/claude_desktop_config.json
  3. Windows: %APPDATA%\Claude\claude_desktop_config.json
  1. Add the
Read from source at commit fec8e044b3cfOBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-pa-ai-agent --env DUCKDUCKGO_API_KEY=${DUCKDUCKGO_API_KEY} --env GOOGLE_ACCESS_TOKEN=${GOOGLE_ACCESS_TOKEN} --env GOOGLE_CLIENT_SECRET=${GOOGLE_CLIENT_SECRET} --env GOOGLE_REFRESH_TOKEN=${GOOGLE_REFRESH_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-pa-ai-agent": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "DUCKDUCKGO_API_KEY": "${DUCKDUCKGO_API_KEY}",
        "GOOGLE_ACCESS_TOKEN": "${GOOGLE_ACCESS_TOKEN}",
        "GOOGLE_CLIENT_SECRET": "${GOOGLE_CLIENT_SECRET}",
        "GOOGLE_REFRESH_TOKEN": "${GOOGLE_REFRESH_TOKEN}"
      }
    }
  }
}
03

Exposed tools (19)

12 read · 6 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_taskwriteAdd a new task.
control_devicereadControl a smart home device.
create_chartwriteCreate a chart from data points.
create_eventwriteCreate a new calendar event.
create_scenewriteCreate a new scene with defined device states.
delete_taskdestructiveDelete a task.
get_device_statereadGet the current state of a smart home device.
get_emailsreadGet recent emails from a specific label.
get_eventsreadGet upcoming calendar events.
get_free_timereadFind free time slots in your calendar for a specific date.
get_newsreadGet latest news, optionally filtered by topic.
get_weatherreadGet current weather information for a location.
list_devicesreadList all available smart home devices.
list_tasksreadList tasks with optional filtering by status.
read_emailreadRead the full content of a specific email.
search_emailsreadSearch emails using Gmail search syntax.
send_emailwriteSend an email.
update_task_statuswriteUpdate the status of a task.
web_searchreadSearch the web for information.
04

Trust audit

SAFEgrade B · trust 86/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (12)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_task
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/modules/calendar/index.js:6
import config from '../../config/index.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/modules/calendar/index.js:7
import logger from '../../utils/logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/modules/calendar/providers/google.js:7
import logger from '../../../utils/logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/modules/calendar/providers/google.js:8
import config from '../../../config/index.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/modules/email/index.js:6
import logger from '../../utils/logger.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@anthropic-ai/mcp-server, dotenv, express, googleapis, ioredis, node-cron, node-fetch, nodemailer
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, httpx, python-dotenv, google-api-python-client, google-auth-oauthlib, redis, python-crontab
Why it matters. 7 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
MCP Python SDK README.md:365
For more control, you can use the low-level server implementation directly. This gives you full access to the protocol and allows you to customize every aspect of your server, including lifecycle mana
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
MCP llms-full P.txt:3307
load_dotenv()  # load environment variables from .env
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
MCP llms-full P.txt:3891
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-09 · audit v0.4.1 · source sha fec8e044b3cffull audit observations/trust-audit/mcp-server/zhangzhongnan928__personal-assistant-agent.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09fec8e044b3cfSAFEB86first audit
06

Questions

What is the Personal Assistant Agent MCP server?

A personal assistant AI agent built with the Model Context Protocol (MCP)

What tools does Personal Assistant Agent expose?

19 in total: 12 read-only, 6 that write, and 1 that can delete or overwrite (delete_task). Every one is listed on this page with its risk.

Is Personal Assistant Agent safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (86/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Personal Assistant Agent need?

It reads DUCKDUCKGO_API_KEY, GOOGLE_ACCESS_TOKEN, GOOGLE_CLIENT_SECRET, GOOGLE_REFRESH_TOKEN, HOME_ASSISTANT_TOKEN, NEWS_API_KEY, REDIS_PASSWORD and WEATHER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Personal Assistant Agent run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-pa-ai-agent at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (fec8e044b3cf), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement