mcp-server-excelBLOCK
Automate real Microsoft Excel with AI via MCP Server or CLI — Power Query, DAX, VBA, PivotTables, charts, and 326 operations.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://marketplace.visualstudio.com/items?itemName=sbroenne.excel-mcp) [](https://github.com/sbroenne/mcp-server-excel/releases)
[](https://github.com/sbroenne/mcp-server-excel/actions/workflows/ci.yml) [](https://github.com/sbroenne/mcp-server-excel/releases/latest)
[](https://opensource.org/licenses/MIT) [](https://dotnet.microsoft.com/download/dotnet/10.0) [](https://github.com/sbroenne/mcp-server-excel) [](https://copilot.github.com/)
**Website** · **Installation** · **Features** · **Troubleshooting** · **2-minute demo**
Automate real Microsoft Excel with AI. Excel MCP Server lets GitHub Copilot, Claude, ChatGPT, and other agents control Excel through natural-language requests—using either MCP or a token-efficient CLI.
Unlike file-parser tools, ExcelMcp drives the actual Excel application through its official COM API. It can refresh Power Query, recalculate formulas, evaluate DAX, run VBA and Python =PY(), and preserve PivotTables, charts, macros, the Data Model, and workbook formatting.
31 tools with 387 operations cover en
18ad41dca727OBSERVED · 2026-10-05Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-server-excel -- npx -y @sbroenne/[email protected]
Exposed tools (1)
0 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
workspace | write | Read/list supplied task files and skill references, or write JSON, CSV, M, and text inputs in the task folder. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
$tokenUri = 'http://169.254.169.254/metadata/identity/oauth2/token' +
02a.wav
02b.wav
02c.wav
$tokenUri = 'http://169.254.169.254/metadata/identity/oauth2/token' +
world-in-motion.xlsx
batch-test-static.xlsx
.vscodeignore
../../../../mcp-publisher.exe publish --verbose
# Many pulled-in source READMEs contain repo-relative links (e.g. ../../FEATURES.md)
self.rewrite("../../src/ExcelMcp.Core/Foo.cs"),self.assertEqual(self.rewrite("../../scripts/"), f"[x]({REPO_URL}/tree/main/scripts)")for link in ("https://example.com", "#here", "/faq/", "mailto:[email protected]", "../../../x.md"):Url = $"http://127.0.0.1:{((IPEndPoint)_listener.LocalEndpoint).Port}/evaluation.csv";foreground-child
foreground-child
foreground-child
@changesets/changelog-github, @changesets/cli
@types/node, @types/vscode, @vscode/vsce, oxlint, typescript, vitest
- No elevated privileges are required or requested
- `Workbook.Model` - full access to Data Model object
assignments or access to the dedicated password vault. Only an identity created
read credential blobs, print account names or blindly delete returning caches.
# Add to user PATH (persistent)
# Edit PATH and remove the ExcelMcp directory
Gates applied: no_behavioural_pass.
18ad41dca727full audit observations/trust-audit/mcp-server/sbroenne__mcp-server-excel.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-05 | 18ad41dca727 | BLOCK | D | 69 | first audit |
Questions
What is the mcp-server-excel MCP server?
Automate real Microsoft Excel with AI via MCP Server or CLI — Power Query, DAX, VBA, PivotTables, charts, and 326 operations.
What tools does mcp-server-excel expose?
1 in total: 0 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is mcp-server-excel safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does mcp-server-excel need?
It reads GH_TOKEN and GITHUB_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does mcp-server-excel run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as excel-mcp at 2.2.1.
How current is this page?
The grade is for one exact copy of the source (18ad41dca727), read on 2026-10-05. The repository is watched and re-audited when it changes.