Calendar Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Calendar Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server that gives Claude (and other MCP hosts) full access to Calendar.app on macOS — list, search, create, update, and delete events — across every account configured in Calendar.app (iCloud, Google, Exchange, etc.).
calendar-mcp.mcpb from the latest release.mcpb file — Claude Desktop installs it automaticallynpx @p-l-ta/calendar-mcpOr install globally:
npm install -g @p-l-ta/calendar-mcp
calendar-mcpPoint your MCP host at the calendar-mcp binary (stdio transport). Example config:
{
"mcpServers": {
"calendar-app": {
"command": "npx",
"args": ["@p-l-ta/calendar-mcp"]
}
}
}Grant these to the application that runs the MCP host (Claude Desktop, etc.):
| Permission | Where to grant |
|---|---|
| Full Disk Access | System Settings → Privacy & Security → Full Disk Access |
| Automation → Calendar | System Settings → Privacy & Security → Automation |
The MCP server process inherits permissions from the host application that launches it.
| Tool | Description |
|---|---|
list_calendars | List all calendars with name, color, account, and UUID |
list_events | List events in a date range, including recurring-event occurrences |
get_event | Get full details of a single event by UUID, including attendees |
search_events | Search events by text across title, description, and location |
create_event | Create a new calendar event |
update_event | Update properties of an existing event |
delete_event | Permanently delete an event |
list_calendars, list_events, search_events, get_event) — query Calendar's SQLite database directly for fast, structured results across all accounts. Recurring events are expanded correctly via Calendar's OccurrenceCache table.create_event, update_event, delete_event) — driven by AppleScript automation against Calendar.app, so changes sync to all connected accounts (iCloud, Google, Exchange) just as if you'd made them in the app.npm install
npm run dev # tsx watch — live reload
npm run build # compile TypeScript → dist/
npm run mcpb # build Claude Desktop extension → build/calendar-mcp.mcpb
npm run smoke # smoke-test all 7 tools against live Calendar.app dataNote: npm run smoke requires Terminal.app (or your terminal emulator) to have Full Disk Access, since it reads Calendar.sqlitedb directly.Interactive MCP testing:
npm run build
npx @modelcontextprotocol/inspector node dist/server.jscalendar-mcp is a local MCP server that runs entirely on your Mac. It has no backend, no telemetry, and makes no network requests of its own.
What it accesses:
~/Library/Group Containers/group.com.apple.calendar/Calendar.sqlitedb) — read-only, used for list/search queriesWhat it does NOT do:
All calendar data stays on your device and is only passed to the MCP host (Claude Desktop or another client) as part of normal tool responses. You control exactly which tools Claude can invoke.
MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.