Microsoft FabricCAUTION
MCP server wrapping around the Fabric Rest API
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://badge.fury.io/py/microsoft-fabric-mcp)
A Model Context Protocol server that provides read-only access to Microsoft Fabric resources. Query workspaces, examine table schemas, monitor jobs, and analyze dependencies using natural language.
Features
- 25 tools covering workspaces, lakehouses, tables, jobs, and dependencies
- Read-only operations - uses only GET requests, no risk of data modification
- Smart caching for fast responses
- Works with Cursor, Claude, and other MCP-compatible AI tools
Available MCP Tools
Parameter Note: workspace parameters accept either workspace names (e.g., "DWH-PROD") or workspace IDs. Names are recommended for ease of use.🏢 Core Fabric Management
📊 Data & Schema Management
b4b5b6e414f0OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add microsoft-fabric-mcp -- uvx microsoft-fabric-mcp
{
"mcpServers": {
"microsoft-fabric-mcp": {
"command": "uvx",
"args": [
"microsoft-fabric-mcp"
]
}
}
}Exposed tools (27)
25 read · 0 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
clear_fabric_data_cache | destructive | Clear Fabric data list caches to see newly created resources immediately (ADMIN). |
clear_name_resolution_cache | destructive | Clear global name→ID resolution caches for workspaces and lakehouses (ADMIN). |
get_all_schemas | read | Get schemas for all Delta tables in a Fabric lakehouse. |
get_data_source_usage | read | Analyze where data sources and connections are used across Fabric items (READ-ONLY). |
get_environment_details | read | Get detailed configuration of a Fabric environment (READ-ONLY). |
get_item | read | Get details of a specific Fabric item (READ-ONLY). |
get_item_lineage | read | Get data lineage information for a Fabric item (READ-ONLY). |
get_job_instance | read | Get detailed information about a specific job instance (READ-ONLY). |
get_shortcut | read | Get detailed information about a specific OneLake shortcut (READ-ONLY). |
get_table_schema | read | Get schema for a specific table in a Fabric lakehouse. |
get_workspace | read | Get details of a specific Fabric workspace (READ-ONLY). |
get_workspace_identity | read | Get workspace identity details for a specific workspace (READ-ONLY). |
list_capacities | read | List all Fabric capacities the user has access to (READ-ONLY). |
list_compute_usage | read | Monitor current compute resource consumption across Fabric workloads (READ-ONLY). |
list_connections | read | List all connections the user has permission for across the entire Fabric tenant (READ-ONLY). |
list_environments | read | List all Fabric environments for compute and library management (READ-ONLY). |
list_item_dependencies | read | List dependencies between items in a workspace (READ-ONLY). |
list_item_schedules | read | List all schedules for a specific item - see what |
list_items | read | List all items in a Fabric workspace (READ-ONLY). |
list_job_instances | read | List all job instances for items in a workspace (READ-ONLY). |
list_lakehouses | read | List all lakehouses in a Fabric workspace. |
list_shortcuts | read | List all OneLake shortcuts in a specific Fabric item (READ-ONLY). |
list_tables | read | List all tables in a Fabric lakehouse. |
list_workspace_schedules | read | List ALL schedules across all items in a workspace - see everything that |
list_workspace_shortcuts | read | List all OneLake shortcuts across all items in a workspace (READ-ONLY). |
list_workspaces | read | List all available Fabric workspaces. |
list_workspaces_with_identity | read | List workspaces that have workspace identities configured (READ-ONLY). |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- UNDECLARED (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (4)
.DS_Store
clear_fabric_data_cache, clear_name_resolution_cache
.DS_Store
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass.
b4b5b6e414f0full audit observations/trust-audit/mcp-server/augustab__microsoft-fabric.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | b4b5b6e414f0 | CAUTION | B | 89 | first audit |
Questions
What is the Microsoft Fabric MCP server?
MCP server wrapping around the Fabric Rest API
What tools does Microsoft Fabric expose?
27 in total: 25 read-only, 0 that write, and 2 that can delete or overwrite (clear_fabric_data_cache, clear_name_resolution_cache). Every one is listed on this page with its risk.
Is Microsoft Fabric safe to connect to an agent?
With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Microsoft Fabric need?
No credential environment variables were found in its source, so it appears to need none.
How does Microsoft Fabric run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as microsoft-fabric-mcp.
How current is this page?
The grade is for one exact copy of the source (b4b5b6e414f0), read on 2026-10-09. The repository is watched and re-audited when it changes.