Mcp Personal — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp Personal (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server exposing Gmail, Outlook and Mercadona tools for Cursor and LangChain.
npm installCopy environment variables and fill in your credentials:
cp .env.example .env
# Edit .env with your Google and/or Microsoft app credentialshttp://localhost:3333/oauth2callback or the value you use for GOOGLE_REDIRECT_URI so it does not clash with the MCP server port)..env as GOOGLE_CLIENT_ID and GOOGLE_CLIENT_SECRET.Mail.Read, Mail.Send, User.Read, offline_access..env as AZURE_CLIENT_ID and AZURE_TENANT_ID. Add AZURE_CLIENT_SECRET if applicable.Run once (or when tokens expire) to write gmail-tokens.json and/or outlook-tokens.json in the project root. These files are gitignored.
npm run gmail:auth
npm run outlook:auth# Development
npm run dev
# Production (build first)
npm run build
npm startServer listens on http://0.0.0.0:3000 by default (override with PORT in .env). MCP endpoint: POST http://localhost:3000/mcp.
http://localhost:3000/mcp (or your deployed URL).MCP_API_KEY in .env):Authorization: Bearer <your MCP_API_KEY value>
Example config (structure may vary by Cursor version):
{
"mcpServers": {
"mcp-personal": {
"url": "http://localhost:3000/mcp",
"headers": {
"Authorization": "Bearer YOUR_MCP_API_KEY"
}
}
}
}If you do not set MCP_API_KEY, omit the Authorization header.
| Tool | Description |
|---|---|
echo | Echo back a message (test tool). |
gmail_list | List Gmail messages (maxResults, optional labelIds). |
gmail_get | Get a single Gmail message by ID. |
gmail_send | Send an email via Gmail (to, subject, body). |
outlook_list | List Outlook messages (maxResults, optional folder). |
outlook_get | Get a single Outlook message by ID. |
outlook_send | Send an email via Outlook (to, subject, body). |
mercadona_search | Search Mercadona products (query). Returns name, price, link. Experimental; site may change. |
| Variable | Description |
|---|---|
PORT | Server port (default 3000). |
MCP_API_KEY | Optional API key; if set, clients must send Authorization: Bearer <key>. |
GOOGLE_CLIENT_ID | Gmail OAuth client ID. |
GOOGLE_CLIENT_SECRET | Gmail OAuth client secret. |
GOOGLE_REDIRECT_URI | OAuth redirect URI (e.g. http://localhost:3333/oauth2callback). |
AZURE_CLIENT_ID | Azure app (client) ID. |
AZURE_TENANT_ID | Azure tenant ID (often common). |
AZURE_CLIENT_SECRET | Azure client secret if required by app type. |
GMAIL_TOKENS_PATH | Optional path to Gmail tokens file (default: project root gmail-tokens.json). |
OUTLOOK_TOKENS_PATH | Optional path to Outlook tokens file (default: project root outlook-tokens.json). |
Token files gmail-tokens.json and outlook-tokens.json are created by the auth scripts and must not be committed.
Mercadona: The mercadona_search tool uses Playwright. On first use you may need to install browsers: npx playwright install chromium.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.