by haris-musa
A Model Context Protocol server for Excel file manipulation
# Add to your Claude Code skills
git clone https://github.com/haris-musa/excel-mcp-serverGuides for using mcp servers skills like excel-mcp-server.
Last scanned: 4/21/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-04-21T06:03:02.537Z",
"semgrepRan": false,
"npmAuditRan": true,
"pipAuditRan": true
}See how excel-mcp-server compares with popular alternatives.
excel-mcp-server is an open-source mcp servers skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by haris-musa. A Model Context Protocol server for Excel file manipulation. It has 4,221 GitHub stars.
Yes. excel-mcp-server passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/haris-musa/excel-mcp-server" and add it to your Claude Code skills directory (see the Installation section above).
excel-mcp-server is primarily written in Python. It is open-source under haris-musa on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other MCP Servers skills you can browse and compare side by side. Open the MCP Servers category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh excel-mcp-server against similar tools.
No comments yet. Be the first to share your thoughts!
Top skills in this category by stars
Based on votes and bookmarks from developers who liked this skill
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
A Model Context Protocol server that lets AI assistants create, read and edit Excel workbooks. It needs no Microsoft Excel installation.
clear_range.xlsm files, module by module (never run). Writing VBA
is off unless you start the server with --allow-vba-write (see below)Works with .xlsx, .xlsm (macros are preserved), .xltx and .xltm files.
You need uv. Every client runs the
server with uvx excel-mcp-server stdio; replace /path/to/workbooks with the folder the
server may use.
Claude Desktop (Chat): download excel-mcp-server-<version>.mcpb from the
latest release and open it.
Claude asks which folder the server may use.
Claude Code (the CLI, and the Code tab in Claude Desktop):
claude mcp add excel --scope user -- uvx excel-mcp-server stdio --allow-dir /path/to/workbooks
Cursor (~/.cursor/mcp.json), and most clients that use an mcpServers config:
{
"mcpServers": {
"excel": {
"command": "uvx",
"args": ["excel-mcp-server", "stdio", "--allow-dir", "/path/to/workbooks"]
}
}
}
VS Code with GitHub Copilot (.vscode/mcp.json, note the servers key):
{
"servers": {
"excel": {
"type": "stdio",
"command": "uvx",
"args": ["excel-mcp-server", "stdio", "--allow-dir", "${workspaceFolder}"]
}
}
}
OpenAI Codex (CLI, IDE extension and app):
codex mcp add excel -- uvx excel-mcp-server stdio --allow-dir /path/to/workbooks
Gemini CLI:
gemini mcp add -s user excel uvx excel-mcp-server stdio --allow-dir /path/to/workbooks
Devin Desktop:
devin mcp add -s user excel -- uvx excel-mcp-server stdio --allow-dir /path/to/workbooks
Claude Desktop, manual setup: open Settings, Developer, Edit Config, add the mcpServers
JSON above to claude_desktop_config.json, and restart Claude.
Desktop apps often cannot find uvx, because they do not see your shell's PATH (common
on macOS). Use its full path instead, which which uvx prints.
With --allow-dir DIR, the server only opens workbooks inside DIR (subfolders included)
and relative paths such as reports/q1.xlsx start there. Repeat the flag to allow several
folders, or set EXCEL_FILES_PATH (separate folders with : on macOS/Linux and ; on
Windows).
Without --allow-dir, any absolute path to an Excel file works. In every mode the server
only touches Excel files and never silently overwrites an existing workbook.
uvx excel-mcp-server streamable-http --allow-dir /srv/workbooks
Clients connect to http://127.0.0.1:8017/mcp. Workbooks live in the --allow-dir folder
(default ./excel_files), and export_workbook / import_workbook move files between the
server and the client.
The server listens on localhost only. To accept other machines, set a token and a host:
EXCEL_MCP_AUTH_TOKEN=change-me uvx excel-mcp-server streamable-http --host 0.0.0.0
Clients then send Authorization: Bearer change-me. Put a TLS-terminating reverse proxy in
front of it for use across networks.
docker build -t excel-mcp-server .
docker run -p 8017:8017 -v "$PWD/workbooks:/data" -e EXCEL_MCP_AUTH_TOKEN=change-me excel-mcp-server
| Flag | Environment variable | Default | Meaning |
|---|---|---|---|
--allow-dir DIR |
EXCEL_FILES_PATH |
none (stdio), ./excel_files (HTTP) |
Folders workbooks must be in |
--read-only |
EXCEL_MCP_READ_ONLY=1 |
off | Only offer tools that do not change files |
--allow-vba-write |
EXCEL_MCP_ALLOW_VBA_WRITE=1 |
off | Add tools that write VBA macros (see warning below); ignored with --read-only |
--max-file-mb N |
100 |
Largest workbook the server opens | |
--log-level LEVEL |
WARNING |
Logging on stderr | |
--host HOST |
EXCEL_MCP_HOST |
127.0.0.1 |
HTTP listen address |
--port PORT |
EXCEL_MCP_PORT |
8017 |
HTTP port |
EXCEL_MCP_AUTH_TOKEN |
none | Bearer token required on HTTP requests | |
--allow-unauthenticated |
off | Allow a non-local --host without a token |
| Area | Tools |
|---|---|
| Workbooks | create_workbook, describe_workbook, set_workbook_settings, list_workbooks, export_workbook, import_workbook |
| Sheets | describe_sheet, create_sheet, rename_sheet, copy_sheet, delete_sheet, insert_rows_or_columns, delete_rows_or_columns |
| Cells | read_range, write_range, clear_range, copy_range, sort_range, transform_range, find_cells, replace_cells |
| Formatting | format_range, merge_cells, set_sheet_layout, add_conditional_format, add_data_validation |
| Objects | create_table, edit_table, create_chart, delete_chart, create_pivot_table, delete_pivot_table, add_slicer, delete_slicer, insert_image, delete_image, add_sparklines, delete_sparklines |
| Names and notes | set_defined_name, delete_defined_name, set_note, delete_note |
| Macros | read_vba; with --allow-vba-write: write_vba_module, delete_vba_module |
Every parameter is documented in TOOLS.md.
With --allow-vba-write (or EXCEL_MCP_ALLOW_VBA_WRITE=1) the server can set the code of
standard, class, workbook and sheet modules in .xlsm and .xltm files, delete standard and
class modules, and create new .xlsm/.xltm workbooks. The server only stores the code; it
never runs it, and Excel asks before enabling macros. Digitally signed VBA projects are
refused, since any change would invalidate the signature.
Warning: macro code runs with your user's rights once you enable macros in Excel. A model that reads untrusted content could be tricked into writing harmful code. Enable this option only for trusted workflows, keep
--allow-dirnarrow, and read the code before you enable macros. The tools are never offered in--read-onlymode.
WEBSERVICE, HYPERLINK, IMAGE, RTD, CALL, INFO,
INDIRECT, Google Sheets IMPORTXML and others), DDE links and references to other
workbooks are rejected.Please report vulnerabilities privately; see SECURITY.md.
read_range is useful before that, values mode calculates formulas that have no saved
result with a built-in calculator (about 260 functions: math, statistics, financial and
bond, dates, text, lookup, logical, LET, sorting and filtering). Results Excel saved are
always preferred. A formula the calculator cannot reproduce exactly as Excel does (an
unsupported function, a circular reference, or an Excel quirk it does not replicate) is
returned as null and listed in uncalculated with the reason; it is never guessed.
Ranges in a formula are reduced to the formula's own row or column where Excel's ordinary
(not a