Agent-first file management — index local folders and S3 buckets, sync Google Drive, tag, search, and retrieve files via CLI + MCP
- capability exposure inferred + 35
- supply-chain attested + 6
- trust mitigators mixed − 8
attested inferred mixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
grade last moved 1d ago · see ecosystem CVEs →
- C · 38 → B · 33
- A · 3 → C · 38
No known CVEs for this server.
No tool-safety findings — heuristic detectors run on the compute-risk cadence; a finding appears when a tool trips a rule.
analyzed v0.4.1 · analyzer v33 · 6d ago
danger signals18
- over-broad OAuth scope gmail.modify package/dist/index.js :31501
"https://www.googleapis.com/auth/gmail.modify", - over-broad OAuth scope https://mail.google.com/ package/dist/index.js :31503
"https://mail.google.com/" - over-broad OAuth scope https://www.googleapis.com/auth/drive package/dist/index.js :31510
"https://www.googleapis.com/auth/drive", - over-broad OAuth scope https://www.googleapis.com/auth/documents package/dist/index.js :31514
"https://www.googleapis.com/auth/documents", - over-broad OAuth scope https://www.googleapis.com/auth/spreadsheets package/dist/index.js :31518
"https://www.googleapis.com/auth/spreadsheets", - over-broad OAuth scope https://www.googleapis.com/auth/cloud-platform package/dist/index.js :31534
"https://www.googleapis.com/auth/cloud-platform", - over-broad OAuth scope gmail.modify package/dist/mcp/index.js :34945
"https://www.googleapis.com/auth/gmail.modify", - over-broad OAuth scope https://mail.google.com/ package/dist/mcp/index.js :34947
"https://mail.google.com/" - over-broad OAuth scope https://www.googleapis.com/auth/drive package/dist/mcp/index.js :34954
"https://www.googleapis.com/auth/drive", - over-broad OAuth scope https://www.googleapis.com/auth/documents package/dist/mcp/index.js :34958
"https://www.googleapis.com/auth/documents", - over-broad OAuth scope https://www.googleapis.com/auth/spreadsheets package/dist/mcp/index.js :34962
"https://www.googleapis.com/auth/spreadsheets", - over-broad OAuth scope https://www.googleapis.com/auth/cloud-platform package/dist/mcp/index.js :34978
"https://www.googleapis.com/auth/cloud-platform", - over-broad OAuth scope gmail.modify package/dist/server/index.js :29180
"https://www.googleapis.com/auth/gmail.modify", - over-broad OAuth scope https://mail.google.com/ package/dist/server/index.js :29182
"https://mail.google.com/" - over-broad OAuth scope https://www.googleapis.com/auth/drive package/dist/server/index.js :29189
"https://www.googleapis.com/auth/drive", - over-broad OAuth scope https://www.googleapis.com/auth/documents package/dist/server/index.js :29193
"https://www.googleapis.com/auth/documents", - over-broad OAuth scope https://www.googleapis.com/auth/spreadsheets package/dist/server/index.js :29197
"https://www.googleapis.com/auth/spreadsheets", - over-broad OAuth scope https://www.googleapis.com/auth/cloud-platform package/dist/server/index.js :29213
"https://www.googleapis.com/auth/cloud-platform",
- supply-chain +6 supply-chain hub →
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of andreihasna2.