Google Documents Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Google Documents Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server for Google Docs - read and edit documents.
Document Q&A: "What does the contract say about termination clauses?" → reads the doc and pulls out the relevant section.
Meeting-to-doc workflow: After a call, reads the Gemini transcript plus follow-up Slack discussion, then updates your team charter with the decisions made.
Release announcement: "Draft a blog post about the new feature based on the GitHub PRs and Slack discussions in #proj-awesome" → synthesizes technical changes into user-facing content.
Daily planning with persistent context: Your AI assistant reads a "planning log" doc at the start of each day, asks about yesterday's progress, helps you identify today's priority, then updates the doc with your plan. Context carries over across sessions - it remembers what you said you'd do and can follow up.
(These are just examples - any workflow that needs document reading or editing can use this. Use in combination with google-drive-mcp for finding files, deleting, comments, and sharing permissions.)
http://localhost:3000/callback to Authorized redirect URIsGOOGLE_CLIENT_ID='your-client-id' \
GOOGLE_CLIENT_SECRET='your-client-secret' \
MCP_TRANSPORT=http \
npm startThe server runs on http://localhost:3000 by default. Change with PORT=3001.
claude mcp add --transport http google-documents-mcp http://localhost:3000/mcpThis server acts as an OAuth proxy to Google:
graph LR
A[MCP client] <--> B[google-documents-mcp] <--> C[Google OAuth/API]/.well-known/oauth-authorization-server/register returns the Google OAuth client credentials/authorize redirects to Google, encoding the client's callback URL in state/callback receives the code from Google and forwards to the client's callback/token proxies token requests to Google, injecting client credentials/mcp handles MCP requests, using the bearer token to call Google Docs APIThe server holds no tokens or state - it just proxies OAuth to Google.
| Tool | Description |
|---|---|
document_get_raw | Get full raw JSON structure (all tabs, formatting, headers, footers, styles) |
document_get_text | Get plain text content of all tabs |
document_create | Create a new blank document |
document_batch_update | Apply multiple edits atomically (insert, delete, format, etc.) |
document_append | Append text to end of document |
document_insert | Insert text at a specific index |
document_replace | Find and replace text |
The document_batch_update tool supports these operations:
insertText - Insert text at a locationdeleteContentRange - Delete a range of contentreplaceAllText - Find and replace all occurrencesinsertInlineImage - Insert an imageinsertTable - Create a tableinsertTableRow / insertTableColumn - Add rows/columns to tablesdeleteTableRow / deleteTableColumn - Remove rows/columns from tablesinsertPageBreak - Add a page breakcreateNamedRange / deleteNamedRange - Manage named rangescreateParagraphBullets / deleteParagraphBullets - Manage bullet listsdocuments - Full access to read and edit documentsPull requests are welcomed on GitHub! To get started:
npm installnpm run test to run testsnpm run buildVersions follow the semantic versioning spec.
To release:
npm version <major | minor | patch> to bump the versiongit push --follow-tags to push with tags~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.