Excel MCP Server can create, read, update, rename, copy, delete, format, validate, chart, and analyze workbook and worksheet content., File-writing tools can overwrite reports, templates, formulas, charts, and analysis outputs, so review diffs or backups before using it on important workbooks., For Streamable HTTP transport, keep file paths relative to the configured `EXCEL_FILES_PATH` directory and restrict server access to trusted users., Generated formulas, charts, pivot tables, and validation rules should be reviewed before use in financial, operational, or customer-facing work.
Privacy notes
Workbooks can contain personal data, financial records, customer lists, credentials, proprietary metrics, formulas, hidden sheets, comments, and metadata., Workbook contents, file names, formulas, charts, prompts, tool arguments, and generated outputs may be visible to the MCP client and model provider., Protect remote deployments, logs, generated files, and shared workbook paths when handling private or regulated data.
Author
haris-musa
Submitted by
oktofeesh1
Claim status
unclaimed
Last verified
2026-06-05
Decision playbook
Review trust signals before you adopt
Signals are present but mixed. Use the checklist below to confirm the source and operational safety for your environment.
Compare context
Selected
0
Current score
63
Baseline
—
Delta
No baseline selected
No major trust-signal divergence detected in the current selection.
Source and provenance checks
Needs review
Confirm ownership and provenance before trusting install instructions.
Source link availableRequired
Open the canonical repository and verify ownership.
Done
Source provenance statusRequired
Marked as source-backed.
Done
Metadata reviewed
No reviewed flag detected in metadata.
Pending
Safety and privacy checks
Complete
Validate risk disclosures before installation or API wiring.
Safety notes presentRequired
Review the listed safety guidance before running commands.
Done
Privacy notes presentRequired
Review data handling notes before connecting accounts or secrets.
Done
Trust level risk gateRequired
Trust level does not block evaluation.
Done
Package and install checks
Needs review
Check package metadata and artifact integrity signals.
Install payload available
Install or copy payload is available for review.
Done
Package verification flag
No package verification flag provided.
Pending
Checksum metadata
No checksum provided for downloaded artifact.
Pending
Compare-driven decision checks
Needs review
Use compare context to validate trade-offs before adoption.
Compare tray has multiple entries
Add at least one more entry to compare trust differences.
4 safety and 3 privacy notes across 5 risk areas. Review closely: credentials & tokens, network access, third-party handling.
5 areas
SafetyGeneralExcel MCP Server can create, read, update, rename, copy, delete, format, validate, chart, and analyze workbook and worksheet content.
SafetyLocal filesFile-writing tools can overwrite reports, templates, formulas, charts, and analysis outputs, so review diffs or backups before using it on important workbooks.
SafetyNetwork accessFor Streamable HTTP transport, keep file paths relative to the configured `EXCEL_FILES_PATH` directory and restrict server access to trusted users.
SafetyGeneralGenerated formulas, charts, pivot tables, and validation rules should be reviewed before use in financial, operational, or customer-facing work.
PrivacyCredentials & tokensWorkbooks can contain personal data, financial records, customer lists, credentials, proprietary metrics, formulas, hidden sheets, comments, and metadata.
PrivacyThird-party handlingWorkbook contents, file names, formulas, charts, prompts, tool arguments, and generated outputs may be visible to the MCP client and model provider.
PrivacyNetwork accessProtect remote deployments, logs, generated files, and shared workbook paths when handling private or regulated data.
Safety notes
Excel MCP Server can create, read, update, rename, copy, delete, format, validate, chart, and analyze workbook and worksheet content.
File-writing tools can overwrite reports, templates, formulas, charts, and analysis outputs, so review diffs or backups before using it on important workbooks.
For Streamable HTTP transport, keep file paths relative to the configured `EXCEL_FILES_PATH` directory and restrict server access to trusted users.
Generated formulas, charts, pivot tables, and validation rules should be reviewed before use in financial, operational, or customer-facing work.
Privacy notes
Workbooks can contain personal data, financial records, customer lists, credentials, proprietary metrics, formulas, hidden sheets, comments, and metadata.
Workbook contents, file names, formulas, charts, prompts, tool arguments, and generated outputs may be visible to the MCP client and model provider.
Protect remote deployments, logs, generated files, and shared workbook paths when handling private or regulated data.
Prerequisites
Python environment with `uvx` available to the MCP client runtime.
Excel workbooks or a directory where new workbook files can be created.
For remote transports, an `EXCEL_FILES_PATH` directory configured on the server side.
Review rules for which workbooks an agent may read, overwrite, or create.
Excel MCP Server lets MCP clients create, read, and modify Excel workbooks
without requiring Microsoft Excel. It supports workbook and worksheet
operations, formulas, formatting, tables, charts, pivot tables, validation, and
data-analysis workflows.
The upstream README documents stdio, deprecated SSE, and Streamable HTTP
transports. The excel-mcp-server PyPI package exposes the excel-mcp-server
command, and the stdio mode can be launched directly with uvx.
These sources were reviewed on 2026-06-05. Prefer the live repository and
PyPI metadata for current transport support, package version, command name,
environment variables, and tool documentation.
Features
Create, read, and update Excel workbooks and worksheets.
Formula, formatting, font, border, alignment, and conditional-formatting
operations.
Excel table creation and table styling.
Chart generation for common chart types.
Pivot-table creation for data analysis.
Worksheet copy, rename, delete, and management tools.
Range, formula, and data-integrity validation.
Stdio, deprecated SSE, and Streamable HTTP transports.
For Streamable HTTP deployments, configure EXCEL_FILES_PATH on the server side
and keep tool file paths relative to that directory.
Use Cases
Ask Claude to create a workbook from structured data.
Update formulas, formatting, tables, and charts in an existing workbook.
Generate pivot tables for exploratory analysis.
Validate ranges and formulas before sharing a spreadsheet.
Use a remote Excel file workspace with path restrictions for team workflows.
Safety and Privacy
Workbook automation can change important reports quickly. Use reviewed file
scopes, backups, and human approval before overwriting production spreadsheets,
financial models, templates, or customer-facing deliverables.
Excel files often contain hidden sheets, formulas, metadata, private business
metrics, and personal data. Treat workbook contents and generated outputs as
sensitive, especially when using remote transports or model providers.
Duplicate Check
No haris-musa/excel-mcp-server entry, excel-mcp-server package entry, or
matching source URL was found in content/mcp. This is distinct from database,
chart, and document MCP servers because it focuses specifically on Excel
workbook manipulation.
Show that Excel MCP Server is listed on HeyClaude. Paste this Markdown into your README — it renders the badge and links back to this page.
[](https://heyclau.de/entry/mcp/excel-mcp-server)
How it compares
Excel MCP Server side by side with 3 alternatives on trust, install, platform support, and disclosed safety notes — all from reviewed registry metadata.
Official MCP server for agent-device, Callstack's device automation CLI for inspecting, controlling, debugging, recording, and collecting evidence from iOS, Android, TV, macOS, Linux, React Native, Expo, Flutter, and native apps.
✓Excel MCP Server can create, read, update, rename, copy, delete, format, validate, chart, and analyze workbook and worksheet content.
File-writing tools can overwrite reports, templates, formulas, charts, and analysis outputs, so review diffs or backups before using it on important workbooks.
For Streamable HTTP transport, keep file paths relative to the configured `EXCEL_FILES_PATH` directory and restrict server access to trusted users.
Generated formulas, charts, pivot tables, and validation rules should be reviewed before use in financial, operational, or customer-facing work.
✓AntV MCP Server Chart can generate visual outputs from provided data, so review charts before using them in reports, dashboards, or customer-facing material.
Geographic visualization tools may depend on external map services and have regional limitations described by the upstream project.
Disable unsupported or unwanted chart tools with `DISABLED_TOOLS` when an MCP client has compatibility issues or a workflow should expose fewer visualization actions.
Use private rendering infrastructure through `VIS_REQUEST_SERVER` when sensitive datasets should not be sent to the default chart generation service.
✓The unified server can discover and execute many ACI.dev managed functions, so restrict permissions before connecting it to an autonomous agent.
App-specific servers should be preferred when a workflow only needs a small set of integrations.
Connected apps may read, create, update, delete, or send data depending on the selected functions and linked account permissions.
Require human approval before email, calendar, CRM, ticketing, infrastructure, billing, deployment, or account-administration actions.
✓Agent Device MCP exposes structured tools backed by `AgentDeviceClient`; the docs state it does not expose generic shell execution over MCP.
Tools and CLI workflows can open apps, inspect UI, tap, type, scroll, perform gestures, wait, assert state, handle alerts, and close sessions.
Evidence workflows can capture screenshots, recordings, logs, traces, network traffic, performance samples, crash context, React profiles, and replay files.
Mutating commands should run serially against one session, and separate sessions or devices should be used for parallel work.
Prefer dedicated test devices or simulators, and require approval before entering credentials, submitting forms, changing settings, installing apps, sending messages, or touching production accounts.
Privacy notes
✓Workbooks can contain personal data, financial records, customer lists, credentials, proprietary metrics, formulas, hidden sheets, comments, and metadata.
Workbook contents, file names, formulas, charts, prompts, tool arguments, and generated outputs may be visible to the MCP client and model provider.
Protect remote deployments, logs, generated files, and shared workbook paths when handling private or regulated data.
✓Chart data, labels, prompts, generated images, service identifiers, and rendering requests may contain business metrics, personal data, locations, or customer information.
Default chart rendering can involve AntV-hosted services; review data sensitivity before sending private datasets.
Protect custom rendering endpoints, service identifiers, and any generated record links in client configs, logs, screenshots, and shared prompts.
✓Tool names, function arguments, prompts, linked account identifiers, execution results, logs, and connected-service data may pass through ACI.dev, the selected third-party apps, the MCP client, and the model provider.
API keys and linked-account credentials must be protected in client config, environment files, logs, screenshots, and shared prompts.
Review ACI.dev account, tenant, retention, audit-log, and OAuth settings before routing production or customer data through the server.
✓Screenshots, recordings, traces, logs, network dumps, replay files, reports, UI snapshots, typed input, and React profiles can contain private UI state, tokens, request data, customer information, or credentials.
macOS, iOS, Android, and TV automation can expose local app state, notifications, device names, package identifiers, app content, system dialogs, and permission prompts.
Network inspection artifacts may include headers, payloads, session identifiers, URLs, and API data; review before sharing or committing.
Interactive CLI runs may check npm for newer package versions unless `AGENT_DEVICE_NO_UPDATE_NOTIFIER=1` is set.
Prerequisites
Python environment with `uvx` available to the MCP client runtime.
Excel workbooks or a directory where new workbook files can be created.
For remote transports, an `EXCEL_FILES_PATH` directory configured on the server side.
Review rules for which workbooks an agent may read, overwrite, or create.
Node.js and npm available to the MCP client runtime.
Structured data or a clear visualization request.
Optional private chart rendering service if default remote rendering is not appropriate for the data.
Optional tool filtering plan for chart types that should not be exposed to a given agent workflow.
ACI.dev account, API key, and linked account owner ID.
Connected app credentials or linked accounts for the tools the agent should use.
MCP client that can launch Python package commands with environment variables.
Clear allowlist of apps, functions, and user accounts before exposing write-capable tools.
Node.js 22 or newer and `agent-device` installed globally or project-locally.
Xcode tooling for iOS, tvOS, or macOS targets, or Android SDK and ADB for Android targets.
Device, simulator, emulator, TV, macOS, or Linux desktop target that the agent is allowed to automate.
Required local permissions such as Android device trust, iOS Developer Mode, macOS Accessibility, and Screen Recording where applicable.