mail-cal-drive-mcp (rumbitopi/mail-cal-drive-mcp) is an MCP server listed on the M8ven Trust Index. It scores 52 out of 100, grade D. It declares 36 tools. No publisher has claimed this listing.
A self-hosted MCP server for managing email, calendar, and cloud storage across Microsoft 365, Google Workspace, and IMAP accounts, enabling natural language interaction through any MCP client.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
rumbitopi
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
auth_statusList all configured accounts with their connection status
auth_startStart authentication for a new account. Microsoft: returns device code URL. Google: returns OAuth URL. Both require auth_complete afterward. IMAP: completes immediately.
auth_completeComplete a pending authentication flow. For Microsoft, polls for device code completion. For Google, checks if OAuth callback was received.
auth_revokeRemove an account and revoke its credentials
find_free_timeFind available time slots in a date range across one or more accounts
check_conflictsCheck for scheduling conflicts in a time range across one or more accounts
list_calendarsList all calendars for an account
list_eventsList calendar events within a date range
get_eventGet full details of a calendar event
create_eventCreate a new calendar event
update_eventUpdate an existing calendar event
delete_eventDelete a calendar event
list_filesList files in a drive folder
get_fileGet file metadata and details
get_file_contentDownload file content (returns base64 for binary, text for text files)
upload_fileUpload a file to drive. Provide content directly as text or base64.
create_folderCreate a new folder in drive
move_fileMove a file to a different folder
copy_fileCopy a file to a new location
rename_fileRename a file
delete_fileDelete a file (moves to trash by default)
get_storage_quotaGet storage quota and usage information
search_filesSearch for files matching criteria
get_sharingGet sharing information for a file
share_fileShare a file with a user/group or create a public link
unshare_fileRemove sharing permission from a file
list_accountsList all configured email accounts
move_messageMove an email message to a different folder
delete_messageDelete an email message (moves to trash by default)
mark_readMark an email message as read or unread
bulk_mail_actionPerform bulk actions on messages matching criteria
list_foldersList email folders/labels for an account
list_messagesList messages in an email folder
get_attachmentDownload an email attachment. Returns text content for text types, or an embedded blob resource for binary files (PDF, images, etc). Use get_message first to see attachment IDs.
get_messageGet full details of an email message including body
search_messagesSearch for email messages matching criteria across one or more accounts
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
When Vitest UI server is listening, arbitrary file can be read and executed
Multer vulnerable to Denial of Service via memory leaks from unclosed streams
Multer vulnerable to Denial of Service from maliciously crafted requests
Multer Vulnerable to Denial of Service via Uncontrolled Recursion
Multer vulnerable to Denial of Service via deeply nested field names
API_KEYMin 32 chars, used as Bearer tokenLOG_LEVELerror, warn, info, debugTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
36/36 tools missing one or more hints — auth_status (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); auth_start (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); auth_complete (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +33 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tests exist
No test files found
Add tests that exercise each declared tool.
Production dependencies are patched
0 critical, 8 high severity in production deps — multer@1.4.5-lts.2 (high), multer@1.4.5-lts.2 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dev dependencies
1 critical/high in dev-only deps (does not ship to users)
Upgrade dev dependencies when convenient.
Dependency freshness
1/16 production deps stale: rrule@2023-11-10 (2.8y)
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/rumbitopi/mail-cal-drive-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check