← Back to search Server uses network capabilities via: fetch(), net Server uses filesystem capabilities via: fs, fs sync ops, fs/promises, path Server uses shell capabilities via: child_process, spawn() Server uses env_vars capabilities via: process.env
@cocal/google-calendar-mcp
Google Calendar MCP Server with extensive support for calendar management
B
75.5 / 100
Versions
@cocal/google-calendar-mcp2.6.2latestJun 1, 2026
2.6.1Mar 2, 2026
2.6.0Mar 2, 2026
2.4.1Jan 18, 2026
2.4.0Jan 18, 2026
+ show 24 moreshow less
2.3.1Jan 6, 2026
2.3.0Jan 6, 2026
2.2.0Dec 7, 2025
2.1.0Dec 6, 2025
2.0.7Nov 5, 2025
2.0.6Oct 22, 2025
2.0.5Oct 19, 2025
2.0.4Oct 15, 2025
2.0.2Oct 14, 2025
2.0.1Oct 11, 2025
2.0.0Oct 11, 2025
1.4.9Sep 2, 2025
1.4.8Jul 3, 2025
1.4.6Jun 17, 2025
1.4.5Jun 17, 2025
1.4.4Jun 17, 2025
1.4.3Jun 17, 2025
1.4.2Jun 17, 2025
1.4.0Jun 17, 2025
1.3.0Jun 5, 2025
1.2.0-beta.3Jun 4, 2025
1.2.0-beta.2Jun 4, 2025
1.2.0-beta.1Jun 4, 2025
1.2.0-beta.0Jun 4, 2025
@sudomcp/google-calendar-mcp1.4.0latestJun 11, 2025
Tools 1
manage-accounts annotations: verified low
Manage Google account authentication. Actions: 'list' (show accounts), 'add' (authenticate new account), 'remove' (remove account).
action enum account_id string
readOnlyHint false openWorldHint false idempotentHint false destructiveHint true
Permissions 4
network medium filesystem low shell high env_vars low Scan Findings 17
info
Tool 'manage-accounts' annotations are consistent
high
Hardcoded OAuth client secret in nspady-google-calendar-mcp-5f301a0/src/tests/unit/auth/AuthServer.test.ts
high
Hardcoded OAuth client secret in nspady-google-calendar-mcp-5f301a0/src/tests/unit/transports/handlers.test.ts
info
Sandbox failed to start for behavioral verification
medium
Vulnerable dependency: vitest@4.0.18 (GHSA-5xrq-8626-4rwp)
info
package.json metadata
info
Tool: manage-accounts
info
Transport: streamable-http
info
Required env vars (24)
high
High-risk OAuth scope: https://www.googleapis.com/auth/calendar
info
Sandbox failed to start for output poisoning scan
medium
Permission: network access detected
low
Permission: filesystem access detected
high
Permission: shell access detected
low
Permission: env_vars access detected
info
SBOM generated: 277 components
medium
No build provenance detected (SLSA L0)