Excel AgentSAFE
An Excel AI agent that uses MCP tools to let LLMs read, edit, and automate Excel spreadsheets.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This repo consists of two main parts: an Excel MCP server (excel_mcp) and an Excel AI Agent Runner (excel_agent).
Demos
Excel Assistant
See demo/ExcelAssistant for an AI Excel assistant in web application form.
https://github.com/user-attachments/assets/18b6b8b5-0943-4c5b-816b-587f1083311d
Slack Workflow
See demo/SlackExcelWorkflow to make a Slack bot that assists with your Excel work.
https://github.com/user-attachments/assets/40611a73-3d4b-4fd2-8626-eb0c6ee8d3c5
Model Performance
Using our agent, we benchmarked several of the leading models on a verified subset of 50 examples from SpreadsheetBench. The following are the results for Pass@1:
You can run this exact evaluation for yourself in the evals folder.
Environment Setup
conda create -n excel conda activate excel conda install python=3.11 pip install -r requirements.txt pip install -e .
General Usage
Setting up an AI Agent consists of two portions. The Excel MCP server allows all agents to have access to a set of ~30 tools that allow editing of the Excel file directly.
Setting Up Excel MCP Server
import asyncio from excel_mcp.excel_server import mcp async def run_mcp_server(): await mcp.run_sse_async(host="127.0.0.1", port=8765) asyncio.run(run_mcp_server())
Setting Up Excel Agent Runner
from excel_agent.agent_runner import ExcelAgentRunner, TaskInput from excel_agent.config import ExperimentConfig message = #some prompt to edit the Excel file input_file = #path to input Excel file output_file = #path to output Excel file. typically a copy of the input file is created to edit. runner = ExcelAgentRunner( config=ExperimentConfig(model='openrouter:openai/gpt-5.1'), mcp_server_url="http://127.0.0.1:8765/sse", ) task_input = TaskInput( instruction=message,
61a2eb91c78dOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add excel-assistant --env SLACK_APP_TOKEN=${SLACK_APP_TOKEN} --env SLACK_BOT_TOKEN=${SLACK_BOT_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"excel-assistant": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"SLACK_APP_TOKEN": "${SLACK_APP_TOKEN}",
"SLACK_BOT_TOKEN": "${SLACK_BOT_TOKEN}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
request_new_tool | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (6)
"/usr/local/bin/soffice", # macOS Homebrew / manual install
mcp_server_url="http://127.0.0.1:8765/sse",
@jspreadsheet/formula, dompurify, exceljs, jspreadsheet-ce, jsuites, marked, react, react-dom
openpyxl, openai, rich, fastapi, uvicorn, python-dotenv, requests, slack-bolt
media/excel_assistant.mp4
media/slack.mp4
Gates applied: no_behavioural_pass.
61a2eb91c78dfull audit observations/trust-audit/mcp-server/sylvianai__excel-agent.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 61a2eb91c78d | SAFE | B | 89 | first audit |
Questions
What is the Excel Agent MCP server?
An Excel AI agent that uses MCP tools to let LLMs read, edit, and automate Excel spreadsheets.
What tools does Excel Agent expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Excel Agent safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Excel Agent need?
It reads SLACK_APP_TOKEN and SLACK_BOT_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (61a2eb91c78d), read on 2026-10-06. The repository is watched and re-audited when it changes.