Sharepoint Mcp Nodejs — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Sharepoint Mcp Nodejs (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A TypeScript MCP (Model Context Protocol) server for SharePoint file and folder management via Microsoft Graph API.
npm install
npm run buildcp .env.example .env
# Edit .env with your Azure AD and SharePoint detailsRequired environment variables:
AZURE_TENANT_ID - Azure AD tenant IDAZURE_CLIENT_ID - App registration client IDAZURE_CLIENT_SECRET - App registration client secretSHAREPOINT_HOSTNAME - e.g. yourcompany.sharepoint.comSHAREPOINT_SITE_NAME - e.g. YourSiteNameAUTH_FLOW - client_credentials (default) or on_behalf_ofstdio transport (for Claude Desktop):
npm startHTTP transport:
npm run start:http
# Server starts on http://localhost:3000/mcpAdd to your Claude Desktop config (~/Library/Application Support/Claude/claude_desktop_config.json):
{
"mcpServers": {
"sharepoint": {
"command": "node",
"args": ["/path/to/sharepoint-mcp-nodejs/dist/index.js"],
"env": {
"AZURE_TENANT_ID": "your-tenant-id",
"AZURE_CLIENT_ID": "your-client-id",
"AZURE_CLIENT_SECRET": "your-client-secret",
"SHAREPOINT_HOSTNAME": "yourcompany.sharepoint.com",
"SHAREPOINT_SITE_NAME": "YourSiteName"
}
}
}
}| Tool | Description |
|---|---|
List_SharePoint_Folders | List folders in a directory |
Create_Folder | Create a new folder |
Delete_Folder | Delete a folder |
Get_SharePoint_Tree | Recursive tree view (configurable depth) |
List_SharePoint_Documents | List documents with metadata |
Get_Document_Content | Download + extract text (PDF/Word/Excel/text) |
Create_Document_From_Markdown | Convert markdown/text to .docx with optional style template |
Upload_Document | Upload from base64 or text content |
Upload_Document_From_Path | Upload a local file (resumable for >4MB) |
Update_Document | Update existing document content |
Delete_Document | Delete a document |
The Create_Document_From_Markdown tool converts markdown or plain text to a .docx file using Pandoc and uploads it to SharePoint.
Parameters:
content (required) — Markdown or plain text to convertfolder_path (required) — Destination folder in SharePointfile_name (required) — Output filename (e.g. report.docx)template_path (optional) — Path to a .docx template on SharePoint for stylingStyle templates: Create a .docx file in Word with your desired styles (fonts, headings, margins, colors), upload it to SharePoint, then reference it as template_path. Pandoc applies styles from the template to the generated document via --reference-doc.
Prerequisites: Pandoc must be installed. In Docker this is handled automatically. For local development:
# macOS
brew install pandoc
# Ubuntu/Debian
sudo apt-get install pandoc
# Verify
pandoc --versionTest 1 — Basic conversion (no template):
Using MCP Inspector:
npx @modelcontextprotocol/inspector node dist/index.jsCall Create_Document_From_Markdown with:
{
"content": "# My Report\n\n## Introduction\n\nThis is a **test** document with:\n\n- Bullet point 1\n- Bullet point 2\n\n## Data\n\n| Name | Value |\n|------|-------|\n| A | 100 |\n| B | 200 |",
"folder_path": "Shared Documents",
"file_name": "test-report.docx"
}Then verify with Get_Document_Content:
{
"file_path": "Shared Documents/test-report.docx"
}Test 2 — With style template:
Upload_Document_From_Path or manually)Create_Document_From_Markdown with the template:{
"content": "# Styled Report\n\nThis document uses corporate styling.",
"folder_path": "Shared Documents",
"file_name": "styled-report.docx",
"template_path": "Templates/corporate-style.docx"
}Test 3 — Via curl (HTTP transport):
# Initialize session
curl -s -X POST http://localhost:3000/mcp \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"test","version":"0.1.0"}}}'
# Call the tool (use the mcp-session-id from the response headers above)
curl -s -X POST http://localhost:3000/mcp \
-H "Content-Type: application/json" \
-H "mcp-session-id: <SESSION_ID>" \
-d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"Create_Document_From_Markdown","arguments":{"content":"# Hello World\n\nTest document.","folder_path":"Shared Documents","file_name":"curl-test.docx"}}}'/content endpointApp-level access using client ID + secret. Best for server-to-server scenarios.
User-level access by exchanging a user token. Use with HTTP transport where the client sends a Authorization: Bearer <token> header.
See docs/azure-setup.md for detailed Azure Portal setup instructions.
After editing .env with your credentials, build and run with:
docker compose up --build -dThe server will be available at http://localhost:3000/mcp.
After making changes to the source, rebuild and restart (the Docker build compiles TypeScript internally):
docker compose up --build -dTo view logs:
docker compose logs -fnpm run dev # Watch mode for TypeScript compilationnpx @modelcontextprotocol/inspector node dist/index.js~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.