Atlas / MCP servers / mkummer225 / Google Sheets

Google SheetsSAFE

mcp/mkummer225/google-sheets-2

Google Sheets MCP Server ๐Ÿ“Š๐Ÿค–

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
15 6r ยท 9w ยท 0d
Transport
stdio
License
MIT
Stars
138
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) connector for Google Sheets that allows AI agents to interact with spreadsheets directly.

Demo

https://github.com/user-attachments/assets/cc4729d9-4e6e-437b-848b-6da9a09418c3

Setup

  1. Clone this repository:
git clone https://github.com/mkummer225/google-sheets-mcp
cd google-sheets-mcp
  1. Install dependencies:

npm install

  1. Build:

npm run build

  1. Create OAuth credentials in Google Cloud Platform:
  2. Create a new project in Google Cloud Console
  3. Enable the Google Sheets API
  4. Configure the OAuth consent screen
  5. Create OAuth client ID credentials (Desktop application) with an appropriate redirect URI (ex: http://localhost:3000/oauth2callback)
  6. Download the credentials and save as gcp-oauth.keys.json in the dist subdirectory
  1. Start the MCP server (you'll automatically be prompted to authenticate/re-authenticate your Google account when necessary):

npm run start

Usage

Sample config:

{
"mcpServers": {
"google-sheets-mcp": {
"command": "node",
"args": [
"/{path_to_dir}/google-sheets-mcp/dist/index.js"
]
}
}
}

Then you should be able to simply specify your spreadsheetId or ask your agent to create a new one for you.

Available Actions

Read from source at commit 61bf1b548465OBSERVED ยท 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source โ€” not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add google-sheets-mcp --env GSHEETS_CREDENTIALS_PATH=${GSHEETS_CREDENTIALS_PATH} --env GSHEETS_OAUTH_PATH=${GSHEETS_OAUTH_PATH} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "google-sheets-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "GSHEETS_CREDENTIALS_PATH": "${GSHEETS_CREDENTIALS_PATH}",
        "GSHEETS_OAUTH_PATH": "${GSHEETS_OAUTH_PATH}"
      }
    }
  }
}
03

Exposed tools (15)

6 read ยท 9 write ยท 0 destructive.

ToolRiskDescription
create_sheetwriteCreate a new sheet/tab in a Google Spreadsheet
create_spreadsheetwriteCreate a new Google Spreadsheet
edit_cellwriteEdit a cell in a Google Sheet
edit_columnwriteEdit an entire column in a Google Sheet
edit_rowwriteEdit an entire row in a Google Sheet
insert_columnwriteInsert a new column at specified position in a Google Sheet
insert_rowwriteInsert a new row at specified position in a Google Sheet
list_sheetsreadList all sheets/tabs in a Google Spreadsheet
read_all_from_sheetreadRead all data from a specified sheet in a Google Spreadsheet
read_columnsreadRead columns from a Google Sheet
read_headingsreadRead the column headings from a Google Sheet
read_rowsreadRead rows from a Google Sheet
refresh_authreadRefresh Google Sheets authentication when credentials expire
rename_docwriteRename the Google Spreadsheet
rename_sheetwriteRename a sheet/tab in a Google Spreadsheet
04

Trust audit

SAFEgrade B ยท trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (1)

LOWSupply chain ยท supply.unpinned ยท CWE-829, CWE-1357
package.json
@google-cloud/local-auth, googleapis, @types/node, shx, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 ยท audit v0.4.1 ยท source sha 61bf1b548465full audit observations/trust-audit/mcp-server/mkummer225__google-sheets-2.json ยท Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0761bf1b548465SAFEB89first audit
06

Questions

What is the Google Sheets MCP server?

Google Sheets MCP Server ๐Ÿ“Š๐Ÿค–

What tools does Google Sheets expose?

15 in total: 6 read-only, 9 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Google Sheets safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Google Sheets need?

It reads GSHEETS_CREDENTIALS_PATH and GSHEETS_OAUTH_PATH from the environment. Give it a token scoped to the least it needs โ€” an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Google Sheets run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as google-sheets-mcp at 0.0.1.

How current is this page?

The grade is for one exact copy of the source (61bf1b548465), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement