excel-mcp-serverBLOCK
A Model Context Protocol server for Excel file manipulation
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://pypi.org/project/excel-mcp-server/) [](https://pepy.tech/project/excel-mcp-server) [](https://github.com/haris-musa/excel-mcp-server/actions/workflows/ci.yml) [](LICENSE)
A Model Context Protocol server that lets AI assistants create, read and edit Excel workbooks. It needs no Microsoft Excel installation.
- Read and write cells, formulas (with results calculated for you) and dates, with paging and streaming reads for large sheets, and search
- Format fonts, fills, borders, number formats, column widths and frozen panes; hide or
group rows, columns and sheets; set up printing; protect sheets
- Structure sheets, rows and columns, merged cells, tables, charts, images and PivotTables
- Rules: conditional formatting and data validation (dropdowns, number limits)
- Macros: read the VBA code in
.xlsmfiles, module by module (never run). Writing VBA
is off unless you start the server with --allow-vba-write (see below)
- Safe by design: optional folder confinement, a formula safety check, read-only mode,
localhost-only HTTP by default, and atomic saves that never leave a half-written file
Works with .xlsx, .xlsm (macros are preserved), .xltx and .xltm files.
Quick start
You need uv. Every client runs the server with uvx excel-mcp-server stdio; replace /path/to/workbooks with the folder the server may use.
**Claude Desktop (Chat
16b6c025e819OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add excel-mcp-server -- uvx excel-mcp-server==1.1.2 stdio
Trust audit
BLOCKgrade D · trust 61/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- declared (5 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (18)
@function("SEQUENCE", kind="scalar")@function("SORT", array=(0,))@function("SORTBY", array=True)@function("UNIQUE", array=(0,))@function("FILTER", kind="raw", array=(0, 1))macro01.xlsm
vbaProject.bin
.mcpbignore
@pytest.mark.parametrize("raw", ["../outside.xlsx", "a/../../outside.xlsx"])curl -s -o /dev/null http://127.0.0.1:8017/mcp && break
Clients connect to `http://127.0.0.1:8017/mcp`. Workbooks live in the `--allow-dir` folder
async with Client(f"http://127.0.0.1:{port}/mcp") as client:bytes.fromhex("D0CF11E0A1B11AE1")content = base64.b64decode(content_base64, validate=True)
return _sha512_hash(current, password) == b64decode(current.hashValue)
digest = sha512(b64decode(current.saltValue) + password.encode("utf-16-le")).digest()_VERSION_INDEPENDENT_PROJECT = bytes.fromhex("cc61ffff000000")Gates applied: no_behavioural_pass.
16b6c025e819full audit observations/trust-audit/mcp-server/haris-musa__excel-mcp-server.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 16b6c025e819 | BLOCK | D | 61 | first audit |
Questions
What is the excel-mcp-server MCP server?
A Model Context Protocol server for Excel file manipulation
Is excel-mcp-server safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (61/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does excel-mcp-server need?
It reads EXCEL_MCP_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does excel-mcp-server run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as excel-mcp-server.
How current is this page?
The grade is for one exact copy of the source (16b6c025e819), read on 2026-10-08. The repository is watched and re-audited when it changes.