github not yet analyzed

Google Sheets

github

Read, write, and format spreadsheet data. Manage sheets, run formulas, and collaborate on structured data in real time.

maintainer
googlesheets
license
first seen
2026-05-22
last seen
2026-06-17
releases · 30d
0
short id
risk 37/100 · heuristic grade
C elevated

Source not yet analyzed — this grade rests on attested signals (CVEs, supply-chain) only. It is a floor: reading the code could raise it, not lower it.

  • capability exposureinferred+26
  • recent driftinferred+5
  • tool safetyinferred+14
  • trust mitigatorsmixed−8

inferredmixed

The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.

graded 13m ago · see ecosystem CVEs →

risk trajectory 3 movements
  • C · 39C · 37
  • B · 18C · 39
  • B · 24B · 18
capability exposure grade factor +26
Inferred surface — each links to servers holding it:
vulnerabilities 0 CVEs

No known CVEs for this server.

tool safety 2 findings · grade factor +14
  1. hightoxic flow (lethal trifecta)

    lethal trifecta reachable across this server's tools: private-data access + untrusted-content ingestion + network exfil

  2. lowexfiltration comboGOOGLESHEETS_UPSERT_ROWS

    single tool reads + sends: net, db

other grade factors evidence elsewhere
embed badge readme-ready
live risk-grade badge preview [![MCP Observatory risk grade](https://mcpobservatory.com/servers/smithery:googlesheets/badge.svg)](https://mcpobservatory.com/servers/smithery:googlesheets/security)

Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of googlesheets.