Sharepoint Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Sharepoint Mcp (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
A bulleted imperative like {match} tells the agent to never reveal, disclose, or mention something to the user. Used adversarially it can instruct the agent to hide its tool calls or lie about what it did — stripping the transparency a user relies on to trust the agent.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
DISCLAIMER: This project is not affiliated with, endorsed by, or related to Microsoft Corporation. SharePoint and Microsoft Graph API are trademarks of Microsoft Corporation. This is an independent, community-driven project.
SharePoint MCP Server is a Model Context Protocol (MCP) server that connects LLM applications such as Claude to your SharePoint site via the Microsoft Graph API. Use natural language to query documents, manage lists, upload files, and more — directly from your AI assistant.
| Category | Capability |
|---|---|
| Site | Get site information |
| Libraries | Browse document libraries, list folder contents |
| Documents | Read DOCX, PDF, XLSX, CSV, TXT; browse by path; get item metadata; upload files |
| Search | Full-text search across all site content |
| Lists | Create lists with AI-optimized schemas; create, update list items |
| Pages | Create modern pages and news posts |
| Provisioning | Create new SharePoint sites and advanced document libraries |
| Transport | stdio (local), SSE, streamable-http (web / Docker) |
git clone https://github.com/DEmodoriGatsuO/sharepoint-mcp.git
cd sharepoint-mcp
python -m venv venv
source venv/bin/activate # Windows: venv\Scripts\activate
pip install -r requirements.txtcp .env.example .env
# Edit .env with your Azure AD credentials and SharePoint site URLRequired variables in .env:
| Variable | Description |
|---|---|
TENANT_ID | Azure AD tenant ID |
CLIENT_ID | Azure AD application (client) ID |
CLIENT_SECRET | Azure AD client secret |
SITE_URL | SharePoint site URL (https://{tenant}.sharepoint.com/sites/{name}) |
python config_checker.py # Validate configuration
python auth-diagnostic.py # Test authentication# stdio — default, for Claude Desktop / MCP Inspector
python server.py
# HTTP streamable-http — for web services and Copilot agents
python server.py --transport streamable-http --port 8000
# Docker
docker-compose upInstall the server into Claude Desktop:
mcp install server.py --name "SharePoint Assistant"Or add it manually to claude_desktop_config.json:
{
"mcpServers": {
"sharepoint": {
"command": "python",
"args": ["/absolute/path/to/sharepoint-mcp/server.py"],
"env": {
"TENANT_ID": "...",
"CLIENT_ID": "...",
"CLIENT_SECRET": "...",
"SITE_URL": "..."
}
}
}
}mcp dev server.py# streamable-http (recommended for Copilot agents and web clients)
python server.py --transport streamable-http --host 0.0.0.0 --port 8000
# SSE
python server.py --transport sse --host 0.0.0.0 --port 8000
# Via environment variables
MCP_TRANSPORT=streamable-http MCP_PORT=8000 python server.py# Build and start (defaults to streamable-http on port 8000)
docker-compose up
# Or run manually
docker build -t sharepoint-mcp .
docker run --env-file .env -p 8000:8000 sharepoint-mcpThe following MCP tools are exposed to the LLM:
| Tool | Description |
|---|---|
get_site_info | Get name, description, URL, and metadata of the SharePoint site |
list_document_libraries | List all document libraries (drives) in the site |
list_folder_contents | Browse files and folders within a document library by path |
get_document_content | Read and parse DOCX, PDF, XLSX, CSV, or TXT files |
get_document_by_path | Retrieve document content by file path |
get_item_metadata | Get metadata for a file or folder |
search_sharepoint | Full-text search across all content in the site |
upload_document | Upload a file to a document library |
create_list_item | Create a new item in a SharePoint list |
update_list_item | Update an existing item in a SharePoint list |
create_intelligent_list | Provision a list with an AI-optimized schema |
create_advanced_document_library | Create a document library with rich metadata |
create_modern_page | Publish a modern SharePoint page |
create_news_post | Publish a news article to the site |
create_sharepoint_site | Provision a new SharePoint team site |
For detailed usage examples and example prompts, see docs/usage.md.
The server writes logs to stdout. Set DEBUG=True in .env to enable verbose logging.
| Symptom | Resolution |
|---|---|
| Authentication failure | Run python auth-diagnostic.py to diagnose |
| Permission errors | Verify your Azure AD app has the required Graph API permissions |
| Token issues | Run python token-decoder.py to inspect token claims |
Contributions are welcome. Please open an issue first to discuss significant changes. See CONTRIBUTING.md for guidelines.
All contributions must pass the quality checks before merge:
black . # Formatting
ruff check . # Linting
pytest # TestsReleased under the MIT License. See LICENSE for details.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.