# GOOGLESUPER_DELETE_DRAFT

Permanently deletes a specific Gmail draft using its ID; ensure the draft exists and the user has necessary permissions for the given user_id.

Agent View of the PolicyLayer registry record for `GOOGLESUPER_DELETE_DRAFT`. HTML page: https://policylayer.com/tools/googlesuper/googlesuper-delete-draft

## Facts

- Tool: `GOOGLESUPER_DELETE_DRAFT`
- Server: Google Super (`googlesuper`) — https://policylayer.com/tools/googlesuper.md
- Install: `npx -y googlesuper`
- Homepage: https://www.npmjs.com/package/googlesuper
- Risk category: Destructive (Critical risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 2
- Recommended policy verdict: Hidden

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `user_id` | string | no | User's email address or 'me' for the authenticated user; 'me' is recommended. |
| `draft_id` | string | no | Immutable ID of the draft to delete, typically obtained when the draft was created. |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "GOOGLESUPER_DELETE_DRAFT",
    "arguments": {}
  }
}
```

## Why GOOGLESUPER_DELETE_DRAFT is rated Critical

This tool destroys data that cannot be recovered. Permanent deletion of Gmail drafts is an irreversible action. While the blast radius is somewhat limited to a single draft (not organization-wide), the destructive nature and the fact that users may have unsaved work in drafts elevates this to 'high' severity. An AI agent misusing this could permanently erase users' draft messages without recovery options.

From the tool's own definition: "'Permanently deletes a specific Gmail draft' — the verb 'deletes' combined with the adverb 'permanently' clearly indicates irreversible data destruction."

## Use case

AI agents call GOOGLESUPER_DELETE_DRAFT to permanently remove resources in Google Super, typically in cleanup and lifecycle workflows. It does its job in a single call, and there is no undo.

## Recommended policy (PolicyLayer)

Verdict: **Hidden**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Google Super:

```json
{
  "version": "1",
  "default": "deny",
  "hide": [
    "GOOGLESUPER_DELETE_DRAFT"
  ]
}
```

## Other tools on Google Super (199)

- `GOOGLESUPER_BATCH_DELETE_MESSAGES` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-batch-delete-messages.md
- `GOOGLESUPER_CALENDARS_DELETE` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-calendars-delete.md
- `GOOGLESUPER_CLEAR_BASIC_FILTER` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-clear-basic-filter.md
- `GOOGLESUPER_CLEAR_CALENDAR` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-clear-calendar.md
- `GOOGLESUPER_CLEAR_TASKS` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-clear-tasks.md
- `GOOGLESUPER_CLEAR_VALUES` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-clear-values.md
- `GOOGLESUPER_DELETE_COMMENT` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-comment.md
- `GOOGLESUPER_DELETE_CONTENT_RANGE` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-content-range.md
- `GOOGLESUPER_DELETE_DIMENSION` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-dimension.md
- `GOOGLESUPER_DELETE_DRIVE` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-drive.md
- `GOOGLESUPER_DELETE_EVENT` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-event.md
- `GOOGLESUPER_DELETE_FOOTER` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-footer.md
- `GOOGLESUPER_DELETE_HEADER` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-header.md
- `GOOGLESUPER_DELETE_MESSAGE` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-message.md
- `GOOGLESUPER_DELETE_NAMED_RANGE` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-named-range.md
- `GOOGLESUPER_DELETE_PERMISSION` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-permission.md
- `GOOGLESUPER_DELETE_REPLY` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-reply.md
- `GOOGLESUPER_DELETE_SHEET` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-sheet.md
- `GOOGLESUPER_DELETE_TABLE` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-table.md
- `GOOGLESUPER_DELETE_TABLE_COLUMN` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-table-column.md
- `GOOGLESUPER_DELETE_TABLE_ROW` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-table-row.md
- `GOOGLESUPER_DELETE_TASK` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-task.md
- `GOOGLESUPER_DELETE_TASK_LIST` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-task-list.md
- `GOOGLESUPER_EMPTY_TRASH` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-empty-trash.md
- `GOOGLESUPER_GOOGLE_DRIVE_DELETE_FOLDER_OR_FILE_ACTION` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-google-drive-delete-folder-or-file-action.md
- `GOOGLESUPER_MOVE_TO_TRASH` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-move-to-trash.md
- `GOOGLESUPER_EVENTS_WATCH` — Execute — https://policylayer.com/tools/googlesuper/googlesuper-events-watch.md
- `GOOGLESUPER_EXECUTE_SQL` — Execute — https://policylayer.com/tools/googlesuper/googlesuper-execute-sql.md
- `GOOGLESUPER_QUERY_TABLE` — Execute — https://policylayer.com/tools/googlesuper/googlesuper-query-table.md
- `GOOGLESUPER_AGGREGATE_COLUMN_DATA` — Read — https://policylayer.com/tools/googlesuper/googlesuper-aggregate-column-data.md
- …and 169 more: https://policylayer.com/tools/googlesuper.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=googlesuper · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/googlesuper
