Microsoft Office MCP Server
io.github.mindstone/mcp-server-office
Read and edit Word documents, Excel workbooks, and PowerPoint presentations via desktop Microsoft 365.
What is the Microsoft Office MCP server?
The Microsoft Office MCP server enables reading and editing Word documents, Excel workbooks, and PowerPoint presentations from desktop Microsoft 365 through an Office Add-in sidecar. It integrates with MCP hosts like Claude Desktop and Cursor to provide direct document manipulation capabilities.
This server connects your AI agent to Microsoft Office applications on your desktop, allowing you to programmatically read and modify Word, Excel, and PowerPoint files. Use it to automate document editing, spreadsheet updates, and presentation changes without manual file handling.
How to install Microsoft Office
Copy-paste configuration for popular MCP clients.
MCP_OFFICE_SIDECAR_STATErequiredAbsolute path to sidecar state file (host-managed; sidecar writes port + token here)
MCP_OFFICE_SIDECAR_DISABLEKill-switch — set to 1 to refuse to spawn or talk to the sidecar
REBEL_DISABLE_OFFICE_SIDECARDEPRECATED legacy alias for MCP_OFFICE_SIDECAR_DISABLE — still honored for backward compatibility with v0.1.1 operator-set kill-switches; will be removed in a future major version. Use MCP_OFFICE_SIDECAR_DISABLE instead.
MCP_OFFICE_SIDECAR_STATE_DIRSidecar state directory (certs, per-app manifests). Normally derived from MCP_OFFICE_SIDECAR_STATE; hosts managing the sidecar lifecycle directly can override.
MCP_OFFICE_ADDIN_DIRAbsolute path to the built add-in static files. Defaults to the package's dist/addin/ directory.
Tools & capabilities
Tools this server exposes to the agent.
Read Word documents— Read content from Word documentsEdit Word documents— Modify and edit Word documentsRead Excel workbooks— Read data and formulas from Excel spreadsheetsEdit Excel workbooks— Modify cells, formulas, and structure in Excel workbooksRead PowerPoint presentations— Read slides and content from PowerPoint presentationsEdit PowerPoint presentations— Modify slides and content in PowerPoint presentations
Use cases
- Automate document generation and updates in Word by programmatically editing templates
- Extract and transform data from Excel spreadsheets and update them with new calculations or values
- Create or modify PowerPoint slides and presentations through code without manual interaction
- Batch process multiple Office documents to apply consistent formatting or content changes
- Generate reports by reading data from Excel and writing summaries to Word documents
Microsoft Office MCP server FAQ
It's an MCP server that connects to desktop Microsoft 365 applications (Word, Excel, PowerPoint) via an Office Add-in sidecar, allowing AI agents to read and edit documents programmatically.
Yes, the server is open-source under the FSL-1.1-MIT license. You need a desktop installation of Microsoft 365 to use it.
Install via npm: `npm install @mindstone/mcp-server-office` or run directly with `npx -y @mindstone/mcp-server-office`. See each host's MCP configuration documentation for setup instructions.
It requires a desktop installation of Microsoft 365 and uses the Office Add-in sidecar for communication—no separate API keys needed.
Word documents, Excel workbooks, and PowerPoint presentations from desktop Microsoft 365 are supported.
Yes, it works with any MCP host including Claude Desktop, Cursor, Rebel, and others.
README (reference)
Source of truth, from the repository.
mcp-servers
Source-available MCP servers by Mindstone. Works with any MCP host — Claude Desktop, Cursor, Rebel, and others.
Browse all 35 connectors with their version, auth model, and tool count at the catalogue site (regenerated from each connector's STATUS.json on every push).
Connectors
| Connector | Description |
|---|---|
| apple-shortcuts | Run and list Apple Shortcuts on macOS via the shortcuts CLI |
| browser-automation | Headless browser control via accessibility snapshots — navigate, fill forms, click, and screenshot pages via the agent-browser CLI |
| elevenlabs | Generate speech, music, and sound effects, browse voices, and transcribe audio via the ElevenLabs API |
| email-imap | Read, search, send, and manage emails through IMAP and SMTP |
| fathom | List and search meetings, view details, read transcripts, and manage teams via Fathom AI |
| freshdesk | Manage helpdesk tickets, search support requests, reply to customers, and add internal notes |
| gamma | Create AI-powered presentations, documents, webpages, and social posts via Gamma |
| google-analytics | Discover GA4 accounts and properties, explore the live schema, and run reports via the Google Analytics API |
| google-workspace | Read, search, and send across Gmail, Calendar, Drive, Docs, Sheets, Slides, Contacts, and Comments with host-orchestrated OAuth and per-account on-disk credentials |
| hubspot | Manage HubSpot CRM — contacts, companies, deals, tickets, leads, tasks, notes, properties, lists, workflows, knowledge base, and files — with multi-account, host-orchestrated OAuth |
| humaans | Query employee profiles, job roles, time-away requests, and company info via Humaans HR |
| kling | Generate AI videos from text descriptions or images via Kling AI |
| microsoft-calendar | List, create, update, and respond to Outlook calendar events, check free/busy, and list calendars; reuses the cohort's host-orchestrated Microsoft 365 OAuth surface |
| microsoft-files | List, search, upload, download, share, and read OneDrive files via Microsoft Graph; reuses the cohort's host-orchestrated Microsoft 365 OAuth surface |
| microsoft-mail | List, search, read, send, reply, forward, draft, move, and delete Outlook email; owns the cohort's host-orchestrated Microsoft 365 OAuth surface |
| microsoft-sharepoint | Discover sites, browse libraries, read pages and lists, search content, and mutate SharePoint files/lists with incremental Sites.Read.All consent |
| microsoft-teams | List and read Teams chats, send chat messages, list teams and channels, and read presence; reuses the cohort's host-orchestrated Microsoft 365 OAuth surface |
| mixmax | Manage sequences, send tracked emails, use templates, and monitor engagement via Mixmax |
| nano-banana | Generate and edit images using Google Gemini's AI capabilities |
| napkin | Generate professional visuals — diagrams, infographics, and illustrations — from text via Napkin AI |
| office | Read and edit Word documents, Excel workbooks, and PowerPoint presentations from desktop Microsoft 365 via an Office Add-in sidecar |
| openai-image | Generate and edit images via OpenAI's gpt-image-2 — sharp text rendering, multilingual support, and four quality levels |
| outreach | Manage prospects, sequences, accounts, tasks, and mailings via the Outreach sales engagement API |
| pandadoc | Create, send, and manage documents, templates, and e-signatures via PandaDoc |
| quickbooks | Manage invoices, bills, customers, vendors, employees, and accounts in QuickBooks Online |
| replit-ssh | Read, write, list, and check files on Replit projects over SSH/SFTP, with one-shot SSH key + config setup on the operator's machine |
| retell-ai | Place voice-agent phone calls, manage agents and LLM prompts, and discover voices via the Retell AI API |
| runway | Generate AI video, images, audio, speech, and sound effects via Runway ML |
| salesforce | Manage accounts, contacts, opportunities, leads, tasks, users, and custom objects via the Salesforce API |
| servicenow | Manage incidents, change requests, users, and knowledge base articles in ServiceNow |
| slack | Multi-workspace Slack — channels, messages, threads, reactions, users, files, bookmarks, and scheduled messages via the Slack Web API, with host-orchestrated OAuth |
| talentlms | Manage users, courses, groups, branches, enrolments, and assessments in TalentLMS |
| vanta | Read and manage compliance posture in Vanta — vulnerabilities, tests, controls, evidence, resources, people, vendors, documents, and compliance summary |
| workday | Query workers, profiles, and organizations in Workday HCM |
| zendesk | Manage tickets, macros, users, and views in Zendesk Support |
Quick Start
Each server builds independently:
cd connectors/<name>
npm install
npm run build
Or run directly via npx (once published):
npx -y @mindstone/mcp-server-zendesk
Moving from
@mindstone-engineering/? Every server has been republished under the shorter@mindstone/npm scope. The legacy@mindstone-engineering/mcp-server-*packages still install but are marked deprecated. See MIGRATION.md for the consumer one-liner and the deprecation timeline.
See each server's README for configuration and host setup instructions. Some connectors require additional environment variables to opt into specific behaviour (e.g. QB_ALLOW_PROD_WRITES for QuickBooks production writes, MCP_WORKSPACE_PATH for sandboxed file reads) — see the per-connector READMEs for the full list.
Security & Hardening
This monorepo follows a defence-in-depth posture for tool-call hosts. Highlights include:
- Workflow safety. GitHub Actions workflows are env-fy'd against script injection (CWE-94), every action is pinned to a commit SHA (kept current by Dependabot), and each job is granted a least-privilege
permissions:block. Publish is split into a build job (does the install/test/pack with no publish credentials) and a publish job (downloads the packed tarball, runs onlynpm publish --ignore-scripts --provenanceunder OIDC trusted publishing, gated by thenpm-publishenvironment). The publish job invokes NO third-party JS —tsc,vitest, lifecycle scripts, etc. all run upstream, away fromid-token: write. See docs/security/AUDIT_FOX-3319_tanstack_supply_chain.md for the supply-chain threat model and docs/security/BRANCH_PROTECTION.md for required GitHub settings. - Release-age cool-down. The repo-level
.npmrcsetsmin-release-age=7(days), so CI refuses to install dependency versions published in the last week. This blocks the "same-day malicious re-publish" path that ships post-npm audit-clean PRs into a release tag. - Provenance-attested releases. Releases are published by CI (
.github/workflows/release.yml) under the@mindstone/npm scope via Trusted Publishing OIDC — no long-lived npm token exists anywhere — with--provenanceSigstore attestations consumers can verify vianpm audit signatures. Every publishable release commit must carry aRelease-Gatetrailer pointing at its pre-release security review, and every publish posts an alert; the full gate chain is in docs/PUBLISH_APPROVAL_PROCESS.md. (Only a brand-new connector's first publish is manual and WebAuthn-gated; those tarballs carry no provenance attestation but remain shasum-verifiable — check out the release commit and runnpm pack; see MIGRATION.md.) - OpenSSF Scorecard. The repo runs the OpenSSF Scorecard weekly via
.github/workflows/scorecard.yml. The report is generated by a third party from the source tree, so every claim above (action pinning, branch protection, token usage, dependency hygiene) is independently checked rather than just asserted here. The current score is shown by the badge at the top of this README.
Recommendations for consumers
These connectors are published as plain npm packages. The strongest single thing you can do to protect yourself from a future supply-chain compromise of any npm package (these or otherwise) is to use a client that does not run lifecycle scripts by default:
- pnpm (
pnpm install/pnpm dlx) — does not executepostinstall/preparehooks unless explicitly allowlisted viaonlyBuiltDependencies. pnpm v11+ also defaults to a 24-hourminimumReleaseAgecool-down. - bun (
bunx) — same default, no lifecycle scripts unless allowlisted. - npm — if you must use npm, set
min-release-age=7andignore-scripts=truein your global~/.npmrc. Requires npm v11.10+ formin-release-age.
None of our published packages need postinstall to function, so disabling lifecycle scripts in your installer of choice is safe.
- Untrusted-content envelopes. External content from email, helpdesk, and ticketing systems (email-imap, freshdesk, zendesk) is wrapped in
<untrusted-content source="...">envelopes with close-tag breakout escaping, so an LLM host can recognise and refuse instruction-injection attempts. - Workspace sandboxing. File-uploading connectors (nano-banana, pandadoc, elevenlabs) constrain reads to
MCP_WORKSPACE_PATH(oros.tmpdir()) with canonical-prefix containment that handles symlinked roots like/tmp→/private/tmp. - Secure-by-default writes. Production-impacting writes (QuickBooks invoices/bills/customers/vendors) require an explicit
QB_ALLOW_PROD_WRITES=1opt-in env var; outreach prospect-enrolment and mixmax sequence-recipient tools carrydestructiveHint: trueso hosts surface confirmation prompts. - SSRF & path traversal. Download connectors (napkin, runway) enforce host allow-lists, manual-redirect handling, and symlink-safe write paths under a configurable root.
- Loopback OAuth bind. Connectors with local OAuth callback servers (salesforce, outreach) hard-code 127.0.0.1, ignoring any
MCP_OAUTH_BIND_HOSToverride. - E.164 validation. Outbound phone-call tools (retell-ai) reject non-E.164 numbers before any upstream API call.
For per-connector security notes, see each connector's README.
To report a vulnerability, please see SECURITY.md.
The Mindstone open-source family
This repo is one of several open-source projects from Mindstone:
- Rebel — the AI workspace desktop app that ships these connectors out of the box (source release in progress).
- Super-MCP — a proxy MCP router that loads only the tools you actually need, saving your context window.
- rebel-system — the public Rebel system: skills, prompts, operators, help docs, and templates.
- meeting-note-recorder — meeting detection, recording, and live transcripts (the Rebel note-taker).
Licence
Each connector is licensed under FSL-1.1-MIT — see the LICENSE file in each connector directory for details.
Related MCP servers

OpenAI Image
Generate and edit images via OpenAI's DALL-E with sharp text rendering and multilingual support.

OpusClip
Clip long-form videos, manage projects and collections with OpusClip integration

Outreach
Manage prospects, sequences, accounts, tasks, and mailings via the Outreach sales engagement API.

PandaDoc
Create, send, and manage documents, templates, and e-signatures via PandaDoc

QuickBooks Online
Manage invoices, bills, customers, vendors, employees, and accounts in QuickBooks Online via MCP.

Replit SSH
Read, write, list, and check files on Replit projects over SSH/SFTP with automatic SSH key setup.