Google Workspace Compliance Audit Tool (sean-m-sweeney/GoogleWorkspaceAudit) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. It declares 28 tools. No publisher has claimed this listing.
An automated security audit tool for Google Workspace environments that assesses compliance with multiple regulatory frameworks using AI-powered analysis and interactive Q\&A workflows.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
sean-m-sweeney
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
start_compliance_auditStart a comprehensive Google Workspace compliance audit. IMPORTANT: Before calling this tool, you MUST first ask the user which compliance framework(s) they want to assess against. Present these options: CMMC (defense contractors), NIST 800-171 (government contractors), NIST CSF (general cybersecuri…
check_2fa_statusCheck if 2FA is enforced for all users in the domain
check_admin_rolesList all users with admin privileges and their role assignments
check_session_settingsCheck session length and timeout settings
check_external_sharingCheck external sharing settings and restrictions
check_api_accessCheck third-party API access and OAuth app permissions
check_groups_external_membersCheck for Google Groups that include external members
check_password_policyCheck password strength and policy requirements
check_inactive_accountsIdentify user accounts that have not logged in for 90+ days
check_audit_log_settingsCheck audit log retention and monitoring configuration
check_suspicious_activityCheck for recent security alerts and suspicious login attempts
check_mobile_devicesCheck mobile device management enrollment and encryption status
check_email_authenticationCheck SPF, DKIM, and DMARC email authentication status
check_email_forwardingCheck for email forwarding rules to external addresses
check_calendar_sharingCheck calendar external sharing settings
check_data_regionsCheck data residency and storage regions
check_shared_drivesCheck shared drive permissions and external access
check_license_utilizationCheck license assignment and utilization
check_storage_usageCheck storage quota usage across users
check_baa_statusCheck HIPAA Business Associate Agreement (BAA) status. Only relevant for HIPAA compliance.
check_less_secure_appsCheck if less secure app access is blocked. Less secure apps use basic authentication which is vulnerable to credential theft.
check_2fa_enforcement_methodCheck the 2FA enforcement method and allowed second factors (security key, phone, etc.)
check_super_admin_recoveryCheck super admin account recovery settings. Weak recovery settings can be exploited to take over admin accounts.
check_advanced_protectionCheck Advanced Protection Program enrollment settings. APP provides the strongest account security for high-risk users.
check_calendar_external_sharing_policyCheck the organization-wide calendar external sharing policy via Policy API.
check_chat_external_restrictionsCheck Google Chat external messaging restrictions. Controls who users can message outside the organization.
check_meet_safetyCheck Google Meet safety settings including host controls and external participant restrictions.
generate_comprehensive_reportGenerate a comprehensive compliance audit report from collected findings. Supports multiple frameworks.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
GOOGLE_WORKSPACE_ADMIN_EMAILecho "=your-admin@yourdomain.com" > ~/workspace-compliance-audit/.envTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
28/28 tools missing one or more hints — start_compliance_audit (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); check_2fa_status (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); check_admin_roles (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +25 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
License file
No license file
Add a LICENSE file (MIT, Apache-2.0, etc.).
Tests exist
No test files found
Add tests that exercise each declared tool.
Production dependencies are patched
0 critical, 1 high severity in production deps — @modelcontextprotocol/sdk@1.25.3 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/sean-m-sweeney/googleworkspaceaudit)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check