Google SheetsSAFE
Google Sheets MCP Server ๐๐ค
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) connector for Google Sheets that allows AI agents to interact with spreadsheets directly.
Demo
https://github.com/user-attachments/assets/cc4729d9-4e6e-437b-848b-6da9a09418c3
Setup
- Clone this repository:
git clone https://github.com/mkummer225/google-sheets-mcp cd google-sheets-mcp
- Install dependencies:
npm install
- Build:
npm run build
- Create OAuth credentials in Google Cloud Platform:
- Create a new project in Google Cloud Console
- Enable the Google Sheets API
- Configure the OAuth consent screen
- Create OAuth client ID credentials (Desktop application) with an appropriate redirect URI (ex: http://localhost:3000/oauth2callback)
- Download the credentials and save as
gcp-oauth.keys.jsonin thedistsubdirectory
- Start the MCP server (you'll automatically be prompted to authenticate/re-authenticate your Google account when necessary):
npm run start
Usage
Sample config:
{
"mcpServers": {
"google-sheets-mcp": {
"command": "node",
"args": [
"/{path_to_dir}/google-sheets-mcp/dist/index.js"
]
}
}
}Then you should be able to simply specify your spreadsheetId or ask your agent to create a new one for you.
Available Actions
61bf1b548465OBSERVED ยท 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source โ not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add google-sheets-mcp --env GSHEETS_CREDENTIALS_PATH=${GSHEETS_CREDENTIALS_PATH} --env GSHEETS_OAUTH_PATH=${GSHEETS_OAUTH_PATH} -- npx -y [email protected]{
"mcpServers": {
"google-sheets-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"GSHEETS_CREDENTIALS_PATH": "${GSHEETS_CREDENTIALS_PATH}",
"GSHEETS_OAUTH_PATH": "${GSHEETS_OAUTH_PATH}"
}
}
}
}Exposed tools (15)
6 read ยท 9 write ยท 0 destructive.
| Tool | Risk | Description |
|---|---|---|
create_sheet | write | Create a new sheet/tab in a Google Spreadsheet |
create_spreadsheet | write | Create a new Google Spreadsheet |
edit_cell | write | Edit a cell in a Google Sheet |
edit_column | write | Edit an entire column in a Google Sheet |
edit_row | write | Edit an entire row in a Google Sheet |
insert_column | write | Insert a new column at specified position in a Google Sheet |
insert_row | write | Insert a new row at specified position in a Google Sheet |
list_sheets | read | List all sheets/tabs in a Google Spreadsheet |
read_all_from_sheet | read | Read all data from a specified sheet in a Google Spreadsheet |
read_columns | read | Read columns from a Google Sheet |
read_headings | read | Read the column headings from a Google Sheet |
read_rows | read | Read rows from a Google Sheet |
refresh_auth | read | Refresh Google Sheets authentication when credentials expire |
rename_doc | write | Rename the Google Spreadsheet |
rename_sheet | write | Rename a sheet/tab in a Google Spreadsheet |
Trust audit
SAFEgrade B ยท trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (1)
@google-cloud/local-auth, googleapis, @types/node, shx, typescript
Gates applied: no_behavioural_pass.
61bf1b548465full audit observations/trust-audit/mcp-server/mkummer225__google-sheets-2.json ยท Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 61bf1b548465 | SAFE | B | 89 | first audit |
Questions
What is the Google Sheets MCP server?
Google Sheets MCP Server ๐๐ค
What tools does Google Sheets expose?
15 in total: 6 read-only, 9 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Google Sheets safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Google Sheets need?
It reads GSHEETS_CREDENTIALS_PATH and GSHEETS_OAUTH_PATH from the environment. Give it a token scoped to the least it needs โ an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Google Sheets run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as google-sheets-mcp at 0.0.1.
How current is this page?
The grade is for one exact copy of the source (61bf1b548465), read on 2026-10-07. The repository is watched and re-audited when it changes.