# manage_scratchpad

Compose, edit, and deliver text content. Use for any multi-line content: emails, documents, descriptions. Compose in the scratchpad, edit by line or JSON path, attach files, then send to any target. For short one-liners, use the service tool directly instead.

Agent View of the PolicyLayer registry record for `manage_scratchpad`. HTML page: https://policylayer.com/tools/aaronsb-google-workspace-mcp/manage-scratchpad

## Facts

- Tool: `manage_scratchpad`
- Server: Google Workspace MCP Server (`aaronsb/google-workspace-mcp`) — https://policylayer.com/tools/aaronsb-google-workspace-mcp.md
- Homepage: https://github.com/aaronsb/google-workspace-mcp
- Risk category: Write (Medium risk)
- Registry record: grade D, identity unverified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Rate-limited

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "manage_scratchpad",
    "arguments": {}
  }
}
```

## Why manage_scratchpad is rated Medium

The tool creates and modifies text content (Write category) and can deliver it via email or other targets. The severity is high because an AI agent could compose and send unauthorized emails, documents, or messages to any recipient, potentially leading to phishing, impersonation, unauthorized communications, or data exfiltration.

From the tool's own definition: "Tool description states 'Compose, edit, and deliver text content' and explicitly mentions 'emails, documents, descriptions' with ability to 'send to any target.' This is clearly a write/modification operation that creates and sends content."

## Use case

AI agents use manage_scratchpad to create or update resources in Google Workspace MCP Server, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Google Workspace MCP Server environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Google Workspace MCP Server:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "manage_scratchpad": {
      "limits": [
        {
          "counter": "manage_scratchpad_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Google Workspace MCP Server (3)

- `queue_operations` — Execute — https://policylayer.com/tools/aaronsb-google-workspace-mcp/queue-operations.md
- `manage_accounts` — Write — https://policylayer.com/tools/aaronsb-google-workspace-mcp/manage-accounts.md
- `manage_workspace` — Write — https://policylayer.com/tools/aaronsb-google-workspace-mcp/manage-workspace.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=aaronsb-google-workspace-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/aaronsb-google-workspace-mcp
