Project: Excel MCP Server
The capstone: build a real Excel MCP server — read tools, SAFE write tools, batch updates, audit trails — applying every discipline from AG-02 through AG-08.
▶ Watch this reelWhat you'll learn
- Read tools first
- Safe write tools
- Batch operations
- Audit, permissions & recap
Remember this
- Read path first: list → read_range → read_table, capped and formula-aware, with sequencing hints in descriptions
- Safe writes = backup + dry-run preview + diff-token confirmation; batch updates are idempotent with structured per-file results
- Audit trail append-only and outside the writable fence; folder scoping is the permission model — the stage's disciplines in one server
Read path
- list_workbooks (call first) · read_range (≤5k cells) · read_table (JSON records).
- openpyxl data_only=False — formulas as strings, documented in description.
Safe writes
- Guardrails: timestamped backup → dry-run preview → diff-token confirmation → bounds.
- Actionable errors for protected sheets, merged cells, formula overwrites.
Batch
- Same change across files: dry_run default true · idempotent (already_applied) · per-file results, partial success by design.
Audit & permissions
- Append-only JSONL log OUTSIDE the writable folder: ts, user, file, range, hashes, backup ref, token.
- ALLOWED-folder scoping = permission model.
Capstone: AG-02→AG-08 embodied in ~300 lines.
Code: The complete tool surface (7 tools, one policy)
# READS (always allowed, capped)
list_workbooks() # map first
read_range(file, sheet, "A1:F50") # ≤5,000 cells
read_table(file, sheet, header_row) # JSON records
# WRITES (guarded: backup → preview → token → bounds)
preview_write(file, sheet, range, values) # → diff + confirm_token
write_cells(..., confirm_token=...) # refuses without valid token
batch_update(sheet, range, values, files,
dry_run=True) # idempotent, per-file results
# EVERYWHERE
# _wb(): ALLOWED-folder scoping (AG-03/07)
# audit.jsonl: append-only, outside fence (AG-07)
# docstrings: when / when-not / limits (AG-02)
# FastMCP + Inspector-tested (AG-08)
#
# Total: ~300 lines. That's the whole production server.