Gws Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Gws Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Model Context Protocol server that gives Claude access to Google Workspace — Gmail, Calendar, Drive, Contacts, Sheets, Docs, Slides, Tasks, and 100+ APIs via the gws CLI.
| Service | Tools | Operations |
|---|---|---|
| Gmail | 10 | send, reply, forward, read, search, list, create draft, update draft, mark read, save attachment to Drive |
| Calendar | 6 | list events, get event, create, update, delete, freebusy |
| Contacts | 7 | search, get, list, create, update, delete, directory search |
| Drive | 3 | search, read file, create folder |
| Sheets | 5 | read, update, append, create, delete |
| Docs | 5 | get, write, batch update, create, delete |
| Slides | 4 | get, create, batch update, delete |
| Tasks | 6 | list task lists, list tasks, create, update, complete, delete |
| Generic | 1 | gws_run — fallback for any GWS API not covered above |
| Auth | 1 | OAuth login and status |
48 tools total. All tools support shared (team) Drives.
gmail_create_draft / gmail_update_draft — Create or replace a Gmail draft. Constructs RFC 2822 MIME messages from structured parameters (to, subject, body, cc, bcc) and base64url-encodes them. gmail_update_draft preserves threading automatically — if no thread_id is provided, it fetches the existing draft's thread ID before replacing the message.
gmail_mark_read — Marks a message as read by removing the UNREAD label. Also supports adding/removing arbitrary labels (STARRED, IMPORTANT, etc.) via add_labels and remove_labels arrays. Always removes UNREAD regardless of other label changes.
gmail_save_attachment_to_drive — Fetches an attachment from Gmail and uploads it directly to Drive server-side. No base64 data flows through the conversation. Uses async file I/O with guaranteed temp file cleanup via try/finally.
drive_search — Searches across both personal and shared Drives. Supports full Drive query syntax including folder parents, mimeType filters, and name matching.
drive_create_folder — Creates a folder in Drive, optionally inside a parent folder.
drive_read_file — Reads the text content of any file in Drive by file ID. Routes by mimeType:
text/plain, text/csv) → raw content fetch{ error: "Unsupported file type: <mimeType>" }docs_get — Three modes:
text (default): plain text with [image:<id>] placeholders for inline images, best for reading/summarizingindex: text with startIndex/endIndex character positions plus inline object references, use before positional editsfull: raw API response, for debugging or style operationsAll modes include the inlineObjects metadata map (contentUri, size, margins, crop, border) when images are present.
docs_create / sheets_create — Return stripped responses with only essential fields:
{ documentId, title }{ spreadsheetId, title, spreadsheetUrl }slides_get / slides_create — Return trimmed responses (no masters, layouts, geometry, styling). Each slide includes:
placeholder_map: maps standard types (TITLE, BODY, SUBTITLE) to objectIdselements: all shapes — both standard placeholders and custom text boxessheets_read — Returns normalized data:
columnCount derived from the widest row (handles empty leading rows correctly)sheets_append — Uses direct Sheets API (spreadsheets.values.append) to preserve 2D array structure. Each inner array becomes a separate row.
docs_write — Uses batchUpdate API with insertText, correctly handles newlines, em dashes, and unicode characters.
gws_run — Fallback tool for any Google Workspace API not covered by the dedicated tools. Accepts service, resource, method, params, and JSON body. Use only when no dedicated tool exists.
Go to Google Cloud Console and create a new project (or use an existing one).
Enable each API you plan to use in your project. Click the links below and hit Enable on each page:
Go to OAuth consent screen:
Go to Credentials:
cp .env.example .envOpen .env and fill in your Client ID and Client Secret from the previous step.
pnpm install
pnpm run build
pnpm run build:extensionThis produces google-workspace-mcp.mcpb.
Open Claude Desktop → Settings → Extensions → Install from file → select google-workspace-mcp.mcpb.
When the extension loads for the first time, a browser window opens automatically for Google OAuth login. Sign in and authorize the app. After that, all tools are ready to use.
Note: If your app is in testing mode (unverified), you'll see a "Google hasn't verified this app" warning. Click Advanced → Go to \<app name\> (unsafe) to proceed. This is safe for personal use.
pnpm install
pnpm run buildWith the env vars from step 5 set, run:
./bin/gws-aarch64-apple-darwin/gws auth login -s drive,gmail,sheets,calendar,docs,slides,people,tasksnode server/index.jsThe MCP server starts on http://localhost:39147/mcp (override with PORT env var).
claude mcp add google-workspace --transport http http://localhost:39147/mcpOr add to Claude Desktop MCP config:
{
"mcpServers": {
"google-workspace": {
"type": "streamable-http",
"url": "http://localhost:39147/mcp"
}
}
}| Variable | Default | Description |
|---|---|---|
PORT | 39147 | HTTP server port |
GWS_OAUTH_CLIENT_ID | — | OAuth client ID |
GWS_OAUTH_CLIENT_SECRET | — | OAuth client secret |
src/
├── create-server.ts # Shared MCP server factory (accepts optional per-session client)
├── extension.ts # Stdio entry point (.mcpb extension, auto-auth on startup)
├── index.ts # HTTP entry point (StreamableHTTP, /health + /mcp endpoints)
├── gws-client.ts # Wrapper around the gws CLI binary, DEFAULT_SERVICES constant
└── tools/
├── response.ts # Response helpers (JSON formatting, 900KB truncation)
├── auth.ts # OAuth login (browser-based, no gcloud needed)
├── gmail.ts # Gmail tools (drafts, mark read, attachments to Drive)
├── calendar.ts # Calendar tools
├── contacts.ts # Contacts / People API tools
├── drive.ts # Drive tools (search, read file, create folder)
├── sheets.ts # Sheets tools (normalized reads, direct API append)
├── docs.ts # Docs tools (text/index/full modes, inline image metadata)
├── slides.ts # Slides tools (trimmed responses, placeholder maps)
├── tasks.ts # Google Tasks tools (lists, CRUD, complete)
├── generic.ts # Generic gws_run fallback
└── index.ts # Tool registry (flat Map<name, handler>)The server wraps the gws CLI binary, which handles OAuth token management and API discovery. Each tool either uses client.helper() for high-level CLI commands or client.api() for direct Google API calls.
The extension (extension.ts) runs via stdio for Claude Desktop .mcpb bundles. The HTTP server (index.ts) runs as a standalone process for Claude Code or other MCP clients. Both share the same createMcpServer() factory.
supportsAllDrives: true (and includeItemsFromAllDrives: true for list operations) so files on team Drives are accessiblecwd: os.tmpdir() and GOOGLE_WORKSPACE_CLI_CONFIG_DIR for Claude Desktop's read-only filesystemoauth.json (injected at build time by scripts/build-extension.sh)X-User-Token header to create per-session clients with pre-obtained access tokens (via GOOGLE_WORKSPACE_CLI_TOKEN env var)inlineObjects map with image metadata (contentUri, size, margins) without embedding actual image bytesdrive_read_file copies Office files with explicit target mimeType to trigger server-side conversion, reads the native copy, then deletes it (guaranteed cleanup via try/finally)drive_read_file only fetches raw content for text/plain and text/csv — all other non-native types return a clean error instead of binary datapnpm run dev # Watch mode — recompiles on changeMIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.