Atlas / MCP servers / haris-musa / excel-mcp-server

excel-mcp-serverBLOCK

mcp/haris-musa/excel-mcp-server

A Model Context Protocol server for Excel file manipulation

Verdict
BLOCK
Grade
D
Trust score
61 /100
Exposed tools
—
Transport
stdio · streamable-http
License
MIT
Stars
4,215
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://pypi.org/project/excel-mcp-server/) [](https://pepy.tech/project/excel-mcp-server) [](https://github.com/haris-musa/excel-mcp-server/actions/workflows/ci.yml) [](LICENSE)

A Model Context Protocol server that lets AI assistants create, read and edit Excel workbooks. It needs no Microsoft Excel installation.

  • Read and write cells, formulas (with results calculated for you) and dates, with paging and streaming reads for large sheets, and search
  • Format fonts, fills, borders, number formats, column widths and frozen panes; hide or

group rows, columns and sheets; set up printing; protect sheets

  • Structure sheets, rows and columns, merged cells, tables, charts, images and PivotTables
  • Rules: conditional formatting and data validation (dropdowns, number limits)
  • Macros: read the VBA code in .xlsm files, module by module (never run). Writing VBA

is off unless you start the server with --allow-vba-write (see below)

  • Safe by design: optional folder confinement, a formula safety check, read-only mode,

localhost-only HTTP by default, and atomic saves that never leave a half-written file

Works with .xlsx, .xlsm (macros are preserved), .xltx and .xltm files.

Quick start

You need uv. Every client runs the server with uvx excel-mcp-server stdio; replace /path/to/workbooks with the folder the server may use.

**Claude Desktop (Chat

Read from source at commit 16b6c025e819OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add excel-mcp-server -- uvx excel-mcp-server==1.1.2 stdio
03

Trust audit

BLOCKgrade D · trust 61/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
declared (5 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (18)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/excel_mcp/calc/functions/arrays.py:25
@function("SEQUENCE", kind="scalar")
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/excel_mcp/calc/functions/arrays.py:57
@function("SORT", array=(0,))
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/excel_mcp/calc/functions/arrays.py:75
@function("SORTBY", array=True)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/excel_mcp/calc/functions/arrays.py:96
@function("UNIQUE", array=(0,))
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/excel_mcp/calc/functions/arrays.py:117
@function("FILTER", kind="raw", array=(0, 1))
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/macro01.xlsm
macro01.xlsm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/vbaProject.bin
vbaProject.bin
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_paths.py:20
@pytest.mark.parametrize("raw", ["../outside.xlsx", "a/../../outside.xlsx"])
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/ci.yml:70
curl -s -o /dev/null http://127.0.0.1:8017/mcp && break
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:114
Clients connect to `http://127.0.0.1:8017/mcp`. Workbooks live in the `--allow-dir` folder
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_transports.py:84
async with Client(f"http://127.0.0.1:{port}/mcp") as client:
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/excel_mcp/cfb.py:226
bytes.fromhex("D0CF11E0A1B11AE1")
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/excel_mcp/operations/files.py:25
content = base64.b64decode(content_base64, validate=True)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/excel_mcp/operations/protection.py:66
return _sha512_hash(current, password) == b64decode(current.hashValue)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/excel_mcp/operations/protection.py:77
digest = sha512(b64decode(current.saltValue) + password.encode("utf-16-le")).digest()
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/excel_mcp/ovba_write.py:20
_VERSION_INDEPENDENT_PROJECT = bytes.fromhex("cc61ffff000000")
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 16b6c025e819full audit observations/trust-audit/mcp-server/haris-musa__excel-mcp-server.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0816b6c025e819BLOCKD61first audit
05

Questions

What is the excel-mcp-server MCP server?

A Model Context Protocol server for Excel file manipulation

Is excel-mcp-server safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (61/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does excel-mcp-server need?

It reads EXCEL_MCP_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does excel-mcp-server run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as excel-mcp-server.

How current is this page?

The grade is for one exact copy of the source (16b6c025e819), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement