Mcp Csv Server — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp Csv Server (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
An MCP server that lets an AI assistant preview, query, aggregate, and convert CSV/TSV data — safely, with no API key.
Give Claude (or any MCP client) the ability to actually work with spreadsheets: filter rows, sum/average/group columns, and turn CSV into JSON — instead of eyeballing a pasted table and guessing. Pure TypeScript, dependency-light, and runnable with zero credentials, so a reviewer can try it in one command.
AIアシスタント(Claude等)に「CSV/業務データを正しく扱う力」を与えるMCPサーバです。表をそのまま 読ませて推測させるのではなく、行の絞り込み・列の集計(合計/平均/最大最小)・グループ集計・JSON変換を ツールとして提供します。APIキー不要で動くので、その場で試せます。
"")・引用符内のカンマ/改行に対応(素朴なsplit(',')が壊れる実データを正しく処理)。[UNKNOWN_COLUMN] Unknown column "x". Hint: Available columns: ... のように、AIにも人にも原因と対処が分かる。csv/(パース・クエリの純粋ロジック)/ tools/(MCPツール定義)/ server.ts(薄い配線)。| Tool | What it does | Key inputs |
|---|---|---|
csv_preview | Columns, total row count, and a sample | csv, delimiter?, limit? |
csv_query | Filter / select / aggregate / group / limit | csv, where?, select?, aggregate?, groupBy?, limit? |
csv_to_json | Convert CSV/TSV to JSON records | csv, delimiter?, limit? |
aggregate supports count, sum, avg, min, max; where ops are eq, ne, gt, gte, lt, lte, contains (ANDed together). Numbers tolerate thousands separators ("2,000" → 2000).
git clone https://github.com/takuyahoritacromtech/mcp-csv-server.git
cd mcp-csv-server
npm install
npm run buildAdd to claude_desktop_config.json:
{
"mcpServers": {
"csv": {
"command": "node",
"args": ["/absolute/path/to/mcp-csv-server/dist/index.js"]
}
}
}Restart the client; the csv_preview, csv_query, and csv_to_json tools appear.
printf '%s\n' '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"smoke","version":"0"}}}' \
| node dist/index.js
# → {"result":{...,"serverInfo":{"name":"mcp-csv-server",...}},"jsonrpc":"2.0","id":1}Given a csv_query call with:
{ "csv": "region,amount\nEast,1000\nWest,2000\nEast,500",
"groupBy": "region",
"aggregate": { "fn": "sum", "column": "amount" } }the tool returns:
{ "columns": ["region", "sum_amount"],
"rows": [{ "region": "East", "sum_amount": 1500 }, { "region": "West", "sum_amount": 2000 }],
"rowCount": 2 }escaped quotes, and embedded delimiters/newlines. This is where naive tools silently corrupt data.
csv/ and tools/ as pure functions, so itis unit-tested without the protocol. server.ts only maps tools to the SDK and converts CsvError into clean tool errors.
UNKNOWN_COLUMN, NON_NUMERIC_COLUMN,CSV_PARSE_ERROR, …) is actionable from the message alone.
any work happens.
npm run check # typecheck + lint + test19 unit tests cover CSV parsing (quoting, TSV, CRLF, ragged rows, empty, unterminated quotes), the query engine (filter/select/aggregate/group/limit + every error code), and the three tools.
MIT © Takuya Horita
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.