Atlas / MCP servers / freema / GSheets

GSheetsBLOCK

mcp/freema/gsheets

MCP server for Google Sheets - Read, write and manipulate spreadsheets through Claude Desktop

Verdict
BLOCK
Grade
D
Trust score
64 /100
Exposed tools
56 28r · 21w · 7d
Transport
stdio
License
MIT
Stars
100
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/mcp-gsheets)

A Model Context Protocol (MCP) server for Google Sheets API integration. Enables reading, writing, and managing Google Sheets documents directly from your MCP client (e.g., Claude Code, Claude Desktop, Cursor, etc.).

Key Features

  • Complete Google Sheets Integration: Read, write, and manage spreadsheets
  • Advanced Operations: Batch operations, formatting, charts, and conditional formatting
  • Flexible Authentication: Support for both file-based and JSON string credentials
  • Production Ready: Built with TypeScript, comprehensive error handling, and full test coverage

Requirements

Getting Started

Quick Install (Recommended)

Add the following config to your MCP client:

{
"mcpServers": {
"mcp-gsheets": {
"command": "npx",
"args": ["-y", "mcp-gsheets@latest"],
"env": {
"GOOGLE_PROJECT_ID": "your-project-id",
"GOOGLE_APPLICATION_CREDENTIALS": "/a
Read from source at commit ca65998c41acOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mcp-gsheets --env GOOGLE_SERVICE_ACCOUNT_KEY=${GOOGLE_SERVICE_ACCOUNT_KEY} --env GOOGLE_PRIVATE_KEY=${GOOGLE_PRIVATE_KEY} -- npx -y [email protected]
03

Exposed tools (56)

28 read · 21 write · 7 destructive. Blast radius: 7 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
analysisTypereadType of analysis:
chartTypereadPreferred chart type:
create-chart-guidewriteStep-by-step guide to create a chart from spreadsheet data
create-tablewriteGuide for creating a new table with headers and data in a Google Spreadsheet
dataDescriptionwriteDescription of the data/table you want to create
dataRangereadThe range containing data for the chart (e.g.,
format-reportreadFormat existing data as a professional report with headers, borders, and styling
rangereadThe range containing data to format (e.g.,
reportStylereadStyle preference:
sheetNamewriteName of the sheet to create the table in (default: Sheet1)
sheets_add_conditional_formattingwriteAdd conditional formatting rules to a Google Sheet
sheets_add_tablewriteCreate a native Google Sheets table with typed columns and optional dropdown values
sheets_append_valuesreadAppend values to the end of a table in a Google Sheets spreadsheet.
sheets_batch_delete_sheetsdestructiveDelete multiple sheets from a Google Sheets spreadsheet in a single operation
sheets_batch_format_cellsreadFormat multiple cell ranges in a Google Sheet in a single operation
sheets_batch_get_valuesreadGet values from multiple ranges in a Google Sheets spreadsheet
sheets_batch_update_valueswriteUpdate values in multiple ranges of a Google Sheets spreadsheet
sheets_check_accessreadCheck access permissions for a spreadsheet. Returns information about what operations are allowed.
sheets_clear_valuesdestructiveClear values in a specified range of a Google Sheets spreadsheet
sheets_compare_rangesreadCompare cell formatting between two ranges of identical dimensions.
sheets_copy_toreadCopy a sheet to another Google Sheets spreadsheet
sheets_create_chartwriteCreate a chart in a Google Sheets spreadsheet. Sheet names with spaces should be quoted in ranges (e.g.,
sheets_create_spreadsheetwriteCreate a new Google Sheets spreadsheet
sheets_delete_chartdestructiveDelete a chart from a Google Sheets spreadsheet
sheets_delete_columnsdestructiveDelete one or more columns from a Google Sheet using a full-column A1 range
sheets_delete_rowsdestructiveDelete one or more rows from a Google Sheet using a full-row A1 range
sheets_delete_sheetdestructiveDelete a sheet from a Google Sheets spreadsheet
sheets_delete_tabledestructiveDelete a native Google Sheets table by tableId
sheets_duplicate_sheetreadDuplicate a sheet within a Google Sheets spreadsheet
sheets_format_cellsreadFormat cells in a Google Sheet (colors, fonts, alignment, number formats)
sheets_get_basic_filterreadRead the Basic Filter (AutoFilter) configuration for a sheet, including the filtered range,
sheets_get_border_mapreadReturns a visual tabular map of borders for a range.
sheets_get_conditional_formattingreadRead conditional formatting rules and banded ranges (alternating row/column colors) for a sheet.
sheets_get_data_validationreadRead data validation rules (checkboxes, dropdown lists, custom formulas, etc.) from a sheet or range.
sheets_get_formatting_compactreadReturns cell formatting for a range as compact A1Range→format pairs.
sheets_get_full_sheet_snapshotreadOne-shot tool: reads all structural and formatting metadata for a sheet in a single API call.
sheets_get_merged_cellswriteGet all merged cell ranges for a specific sheet. Returns each merge as A1 notation and GridRange coordinates.
sheets_get_metadatareadGet metadata about a Google Sheets spreadsheet including sheet names, IDs, and properties
sheets_get_sheet_dimensionsreadGet column widths (pixelSize), row heights (pixelSize), hidden columns/rows, and frozen row/column counts for a sheet.
sheets_get_sheet_formattingreadRead cell formatting (background color, text color, font family, font size, bold, italic,
sheets_get_sheet_structurereadLightweight tool returning ONLY structural/dimensional metadata for a sheet — no per-cell data.
sheets_get_tablesreadRead native Google Sheets tables for a spreadsheet or a specific sheet
sheets_get_valuesreadGet values from a specified range in a Google Sheets spreadsheet
sheets_insert_datewriteInsert properly formatted dates in Google Sheets with locale support and automatic detection
sheets_insert_linkwriteInsert clickable links in Google Sheets cells with custom display text
sheets_insert_rowswriteInsert new rows at a specific position with optional data
sheets_insert_sheetwriteAdd a new sheet to an existing Google Sheets spreadsheet
sheets_merge_cellswriteMerge cells in a Google Sheet
sheets_unmerge_cellsreadUnmerge cells in a Google Sheet
sheets_update_borderswriteUpdate borders of cells in a Google Sheet
sheets_update_chartwriteUpdate an existing chart in a Google Sheets spreadsheet
sheets_update_sheet_propertieswriteUpdate properties of a sheet in a Google Sheets spreadsheet
sheets_update_tablewriteUpdate an existing native Google Sheets table by tableId
sheets_update_valueswriteUpdate values in a specified range of a Google Sheets spreadsheet.
spreadsheetIdreadThe ID of the target spreadsheet (from the URL)
summarize-datawriteAnalyze spreadsheet data and provide insights or create a summary
04

Trust audit

BLOCKgrade D · trust 64/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (14)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
.env.example:11
# GOOGLE_PRIVATE_KEY='-----BEGIN PRIVATE KEY-----\nMIIEvgIBADANBgkqhkiG...\n-----END PRIVATE KEY-----\n'
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/utils/google-auth.ts:99
'It should start with -----BEGIN PRIVATE KEY----- and end with -----END PRIVATE KEY-----'
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
README.md:163
"GOOGLE_SERVICE_ACCOUNT_KEY": "{\"type\":\"service_account\",\"project_id\":\"your-project\",\"private_key_id\":\"...\",\"private_key\":\"-----BEGIN PRIVATE KEY-----\\n...\\n-----END PRIVATE KEY-----\
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
README.md:187
"GOOGLE_PRIVATE_KEY": "-----BEGIN PRIVATE KEY-----\\nMIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQCgR6bvMNOUHZ29\\n+YgbVHAXsT/s+L/jnXTCB193zikCzspSBSfxLu8VRDjkNq9WUoDxizTATzMFNvNf\\n...\\n-----EN
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
README.md:197
- The private key must include the `-----BEGIN PRIVATE KEY-----` and `-----END PRIVATE KEY-----` markers
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
sheets_batch_delete_sheets, sheets_clear_values, sheets_delete_chart, sheets_delete_columns, sheets_delete_rows, sheets_delete_sheet, sheets_delete_table
Why it matters. 7 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/config/toolsets.test.ts:10
} from '../../../src/config/toolsets.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/config/toolsets.test.ts:11
import * as tools from '../../../src/tools/index.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/dotenv-loading.test.ts:8
const INDEX_PATH = path.resolve(__dirname, '../../src/index.ts');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/tools/append-values.test.ts:2
import { handleAppendValues } from '../../../src/tools/append-values.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/tools/append-values.test.ts:3
import * as googleAuth from '../../../src/utils/google-auth.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, googleapis, zod, @eslint/js, @types/node, @vitest/coverage-v8, @vitest/ui, dotenv
Why it matters. 18 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha ca65998c41acfull audit observations/trust-audit/mcp-server/freema__gsheets.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07ca65998c41acBLOCKD64first audit
06

Questions

What is the GSheets MCP server?

MCP server for Google Sheets - Read, write and manipulate spreadsheets through Claude Desktop

What tools does GSheets expose?

56 in total: 28 read-only, 21 that write, and 7 that can delete or overwrite (sheets_batch_delete_sheets, sheets_clear_values, sheets_delete_chart, sheets_delete_columns, sheets_delete_rows). Every one is listed on this page with its risk.

Is GSheets safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (64/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 7 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does GSheets need?

It reads GOOGLE_APPLICATION_CREDENTIALS, GOOGLE_PRIVATE_KEY and GOOGLE_SERVICE_ACCOUNT_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does GSheets run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-gsheets at 1.10.3.

How current is this page?

The grade is for one exact copy of the source (ca65998c41ac), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement