Atlas / MCP servers / felores / Airtable

AirtableBLOCK

mcp/felores/airtable

Search, create and update Airtable bases, tables, fields, and records using Claude Desktop and MCP (Model Context Protocol) clients

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
12 5r · 6w · 1d
Transport
stdio
License
NOASSERTION
Stars
75
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol server that provides tools for interacting with Airtable's API. This server enables programmatic management of Airtable bases, tables, fields, and records through Claude Desktop or other MCP clients.

This MCP server features a specialized implementation that allows it to build tables in stages, leveraging Claude's agentic capabilities and minimizing the failure rate typically seen in other MCP servers for Airtable when building complex tables. It also includes system prompt and project knowledge markdown files to provide additional guidance for the LLM when leveraging projects in Claude Desktop.

Requirements: Node.js

  1. Install Node.js (version 18 or higher) and npm from nodejs.org
  2. Verify installation:
node --version
npm --version

⚠️ Important: Before running, make sure to setup your Airtable API key

Obtaining an Airtable API Key

  1. Log in to your Airtable account at airtable.com
  2. Create a personal access token at Airtable's Builder Hub
  3. In the Personal access token section select these scopes:
  4. data.records:read
  5. data.records:write
  6. schema.bases:read
  7. schema.bases:write
  8. Select the workspace or bases you want to give access to the personal access token
  9. Keep this key secure - you'll need it for configuration

Installation

Method 1: Using npx (Recommended)

  1. Navigate to the Claude configuration directory:
  • Windows: C:\Users\NAME\AppData\Roaming\Claude
  • macOS: ~/Library/Application Support/Claude/

You can also find these directories inside the Claude Desktop app: Claude Desktop > Settings > Developer > Edit Config

  1. Create or edit claude_desktop_config.json:
{
"m
Read from source at commit 74ad4c590fbfOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add airtable-mcp-server --env AIRTABLE_API_KEY=${AIRTABLE_API_KEY} -- npx -y @felores/[email protected]
claude-desktop
{
  "mcpServers": {
    "airtable-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@felores/[email protected]"
      ],
      "env": {
        "AIRTABLE_API_KEY": "${AIRTABLE_API_KEY}"
      }
    }
  }
}
03

Exposed tools (12)

5 read · 6 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
create_fieldwriteCreate a new field in a table
create_recordwriteCreate a new record in a table
create_tablewriteCreate a new table in a base
delete_recorddestructiveDelete a record from a table
get_recordreadGet a single record by its ID
list_basesreadList all accessible Airtable bases
list_recordsreadList records in a table
list_tablesreadList all tables in a base
search_recordsreadSearch for records in a table
update_fieldwriteUpdate a field in a table
update_recordwriteUpdate an existing record in a table
update_tablewriteUpdate a table
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (10)

HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/Airtable API Documentation.md:1
# Airtable API Documentation
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/Airtable API field types and cell values.md:1
# Field types and cell values
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_record
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
axios, @types/node, typescript
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:27
4. Select the workspace or bases you want to give access to the personal access token
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/Airtable API Documentation.md:22
Passing personal access tokens and OAuth access tokens via the legacy `api_key` URL parameter is not supported.
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/Airtable API Documentation.md:30
We currently support using personal access tokens and OAuth access tokens during the authentication process.
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/Airtable API Documentation.md:66
[Personal access tokens](https://airtable.com/developers/web/guides/personal-access-tokens) and [OAuth access tokens](https://airtable.com/developers/web/guides/oauth-integrations) can only access API
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/Airtable API Documentation.md:385
Check that both you and the token have access to the resource. For example, to access a base using a personal access token,
Why it matters. asks the agent to read credentials
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/MCP-llms-full.md:3544
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 74ad4c590fbffull audit observations/trust-audit/mcp-server/felores__airtable.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0774ad4c590fbfBLOCKD69first audit
06

Questions

What is the Airtable MCP server?

Search, create and update Airtable bases, tables, fields, and records using Claude Desktop and MCP (Model Context Protocol) clients

What tools does Airtable expose?

12 in total: 5 read-only, 6 that write, and 1 that can delete or overwrite (delete_record). Every one is listed on this page with its risk.

Is Airtable safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Airtable need?

It reads AIRTABLE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Airtable run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @felores/airtable-mcp-server at 0.3.0.

How current is this page?

The grade is for one exact copy of the source (74ad4c590fbf), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement