Mcp Googletasks — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp Googletasks (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This Model Context Protocol (MCP) server provides a bridge between MCP clients and Google Tasks, allowing you to manage your task lists and tasks directly from clients like Claude Desktop, Cursor, and Codex.
[!NOTE] All (bar some edits) code in this project was "vibe coded" - generated with Claude/Copilot with instructions from me.
This MCP server provides the following functionality:
list-tasklists - List all your task listsget-tasklist - Get details about a specific task listcreate-tasklist - Create a new task listupdate-tasklist - Update an existing task listdelete-tasklist - Delete a task listlist-tasks - List all tasks in a task list, including paginated resultsget-task - Get details about a specific taskcreate-task - Create a new taskupdate-task - Update an existing taskdelete-task - Delete a taskcomplete-task - Mark a task as completedmove-task - Move a task (reorder, change parent, or move across task lists)clear-completed-tasks - Clear all completed tasks from a listCreate a .env file in this project directory:
GOOGLE_CLIENT_ID=your_client_id_here
GOOGLE_CLIENT_SECRET=your_client_secret_here
GOOGLE_REDIRECT_URI=http://localhost:3000/oauth2callbackEnvironment Variables:
GOOGLE_CLIENT_ID (required) - Your Google OAuth Client IDGOOGLE_CLIENT_SECRET (required) - Your Google OAuth Client SecretGOOGLE_REDIRECT_URI (optional) - OAuth redirect URI (defaults to http://localhost:3000/oauth2callback)Note: The server validates that GOOGLE_CLIENT_ID and GOOGLE_CLIENT_SECRET are set at startup and will fail with clear error messages if they are missing or invalid.
npm installnpm run build#### Codex
Add the server to ~/.codex/config.toml:
[mcp_servers.google-tasks]
command = "zsh"
args = ["-lc", "cd /path/to/google-tasks-mcp && exec node build/index.js"]Replace /path/to/google-tasks-mcp with the path to this project, then restart Codex.
To verify the server is registered:
codex mcp list
codex mcp get google-tasks#### Claude for Desktop
~/Library/Application Support/Claude/claude_desktop_config.json%APPDATA%\Claude\claude_desktop_config.json{
"mcpServers": {
"google-tasks": {
"command": "node",
"args": ["/path/to/google-tasks-mcp/build/index.js"]
}
}
}Replace the path with your own value, then restart Claude for Desktop.
When you first use the Google Tasks MCP server:
authenticate tool to get an authorization URLset-auth-code tool with this code to complete authenticationNote: Your authentication tokens (including refresh tokens) are automatically saved to disk at ~/.config/google-tasks-mcp/credentials.json with restricted permissions (600). This means:
package.json engines)This MCP server includes the following improvements:
~/.config/google-tasks-mcp/credentials.json) with restricted permissions, so you only need to authenticate onceGOOGLE_REDIRECT_URI environment variableClaude Desktop Screenshot
Cursor Screenshot
This project is for demonstration purposes only. Use at your own risk.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.