Atlas / MCP servers / guillehr2 / Excel Master

Excel MasterSAFE

mcp/guillehr2/excel-master-1

Excel MCP Server - Manipulate Excel files without Microsoft Excel. Model Context Protocol for XLSX, XLSM with Claude AI integration

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
20 5r · 14w · 1d
Transport
—
License
MIT
Stars
34
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://modelcontextprotocol.io/) [](https://www.npmjs.com/package/@guillehr2/excel-mcp-server) [](https://claude.ai) [](https://mseep.ai/app/d608b999-01ad-40b1-aea1-3c6c6e7bb4f1) [](https://www.python.org/downloads/) [](https://www.npmjs.com/package/@guillehr2/excel-mcp-server) [](https://github.com/guillehr2/Excel-MCP-Server-Master/stargazers) [](https://opensource.org/licenses/MIT)

A Model Context Protocol (MCP) server that lets you manipulate Excel files without needing Microsoft Excel installed. Create, read, write, and analyze Excel workbooks (.xlsx, .xlsm) with AI assistants like Claude. Complete Excel automation through LLM integration.

Key Features:

  • ✅ Read and write Excel files without Microsoft Excel
  • ✅ Full support for XLSX, XLSM, XLTX, XLTM formats
  • ✅ Create charts, pivot tables, and dashboards
  • ✅ Import/export CSV, JSON, SQL, PDF
  • ✅ Works with Claude AI and other LLM assistants
  • ✅ Cross-platform: Windows, macOS, Linux
  • ✅ Easy installation via npm/npx

🌟 Features - Excel MCP Server

Complete Excel Manipulation without Microsoft Excel

  • 📊 Excel file operations: Read and write XLSX, XLSM, XLTX, XLTM files
  • 📖 Data extraction: Read data from Excel sheets with pagination support
  • ✍️ Write operations: Write data and formulas to Excel workbooks
  • **📋
Read from source at commit 0e2e8eb61810OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add excel-mcp-server -- npx -y @guillehr2/[email protected]
claude-desktop
{
  "mcpServers": {
    "excel-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@guillehr2/[email protected]"
      ]
    }
  }
}
03

Exposed tools (20)

5 read · 14 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_calculated_column_toolwriteCreate calculated columns with live Excel formulas for dynamic data analysis.
add_chart_toolwriteCreate native Excel charts with professional styling and intelligent data linking.
add_formula_toolwriteAdd a specific Excel formula to a cell or range of cells.
add_formulas_toolwriteAdd live Excel formulas to create dynamic, self-updating data analysis.
add_sheet_toolwriteAdd a new empty worksheet.
add_table_toolwriteConvert data ranges into native Excel tables with professional formatting and functionality.
create_chart_from_data_toolwriteCreate a chart from new data in one step.
create_formatted_table_toolwriteCreate a formatted table with data in one step.
create_sheet_with_data_toolwriteCreate an Excel file with a single sheet and data in one step.
create_workbook_toolwriteCreate a new empty Excel workbook with optimal foundation for data manipulation.
delete_sheet_tooldestructiveDelete the indicated worksheet.
export_pdf_toolreadExport Excel worksheets to PDF with intelligent automatic handling.
filter_data_toolreadFilter and extract data from a table or range as records.
list_sheets_toolreadList the worksheets available in an Excel file.
open_workbook_toolreadOpen an existing Excel file.
optimize_excel_file_toolreadPerform comprehensive cleanup and optimization of an Excel file.
rename_sheet_toolwriteRename a worksheet.
save_workbook_toolwriteSave the workbook to disk.
update_cell_toolwriteUpdate the value or formula of a specific cell.
write_sheet_data_toolwriteWrite two-dimensional data arrays to Excel with automatic data type optimization.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_sheet_tool
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
cross-spawn
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
fastmcp, openpyxl, pandas, numpy, xlsxwriter, xlrd, xlwt, matplotlib
Why it matters. 9 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 0e2e8eb61810full audit observations/trust-audit/mcp-server/guillehr2__excel-master-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-080e2e8eb61810SAFEB89first audit
06

Questions

What is the Excel Master MCP server?

Excel MCP Server - Manipulate Excel files without Microsoft Excel. Model Context Protocol for XLSX, XLSM with Claude AI integration

What tools does Excel Master expose?

20 in total: 5 read-only, 14 that write, and 1 that can delete or overwrite (delete_sheet_tool). Every one is listed on this page with its risk.

Is Excel Master safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Excel Master need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (0e2e8eb61810), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement