Field-by-field comparison

Compare the evidence before choosing an MCP.

Each signal stays separate, missing facts remain visible, and the column order follows your selection.

MCPs in this comparison

Uncheck an MCP to remove it. Comparing two or three keeps each signal in its own row.

Open canonical comparison link

Comparable alternatives

Shown only when capability or industry context overlaps.

Side-by-side MCP evidence comparison
Evidence fieldCitra (PDF Reader MCP)Watchlist candidateExcel MCP ServerMCP100 Selected
Task fit
Best for
  • Reading and searching PDFs with structured text and tables
  • OCR or rendered PDF evidence with page and bounding-box citations
  • Reading, creating, formatting, charting, and updating XLSX workbooks and worksheets, including formulas and pivot tables
Not ideal for
  • Editing, creating, signing, or rewriting PDF files, which are outside the documented three-tool surface
  • Word, Excel, CSV, or general document workflows outside PDF
  • Workbooks that depend on full desktop Excel behavior, macros, or manual visual review
Avoid when
  • The process can read sensitive PDF directories that have not been explicitly allowlisted
  • You cannot review the Node and platform-native package chain before installation
  • You cannot restrict file access or are using a version affected by CVE-2026-40576
Provenance
Provenance details

First-party MCP

SylphxAI · Publisher source ↗

Community implementation

Haris Musa · Publisher source ↗

Maintenance
Maintenance details

Repo: Aug 8, 2026

Package: Aug 7, 2026

Repo: Apr 12, 2026

Package: Apr 12, 2026

Popularity evidence
GitHub stars

891

GitHub stars · checked 2026-08-14T18:46:26.000Z

4,108

GitHub stars · checked 2026-08-14T18:46:26.000Z

External adoption evidence
  • github: repository stars: 891Exact attributable signal.github: repository stars · Admission snapshot · checked 2026-08-14T18:46:26.000ZEvidence source ↗
  • github: repository stars: 4,108Exact attributable signal.github: repository stars · Admission snapshot · checked 2026-08-14T18:46:26.000ZEvidence source ↗
Client coverage
Client coverage details
Claude CodeLocal stdio
Claude DesktopLocal stdio
CodexLocal stdio
VS CodeLocal stdio
CursorLocal stdio
OpenCodeLocal stdio
Claude CodeLocal stdio
Claude DesktopLocal stdio
CodexLocal stdio
VS CodeLocal stdio
CursorLocal stdio
OpenCodeLocal stdio
Client coverage noteLocal stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server.
Access and data
AuthenticationDefault stdio needs no service credential. Optional HTTP mode supports MCP_API_KEY and binds loopback by default; configured HTTP or OpenAI-compatible visual providers may use their own headers or API key, while local command providers do not inherently require one.Local stdio has no separate service authentication. Remote MCP authentication is not documented, so remote listeners must remain network-restricted.
CostThe MIT-licensed local server has no documented usage fee. Pricing for any operator-selected external OCR, visual, network, or client provider is outside the Citra documentation and remains provider-specific.The MIT-licensed local server lists no usage fee; normal hosting, client, model, and network costs may apply.
PermissionsThe tools read PDF paths and URLs available to the process. Directory allowlists can restrict local reach; URL handling blocks private addresses by default unless the operator overrides it.The server can read, create, modify, format, chart, and delete workbook content. Remote modes confine relative paths to EXCEL_FILES_PATH in the patched release.
Data handlingDefault stdio processing is local. Optional OCR or visual providers may receive rendered content according to their configuration, and URL inputs are fetched from their source.Workbook paths and spreadsheet content are processed by the server and returned to the connected client as required by tool calls; publisher telemetry and retention are not documented.
Limitations
Tradeoffs
  • Local-first PDF processing reduces routine cloud exposure, but optional OCR and visual providers introduce separate dependencies and data paths.
  • The focused three-tool surface is easier to reason about than a general file server, but it deliberately does not cover document editing.
  • It provides deep spreadsheet manipulation without desktop Excel, but write tools can overwrite data and remote transports add network and filesystem exposure.
Risk contextUse stdio, configure explicit allowed PDF directories, retain private-IP URL blocking, require an API key before any non-loopback HTTP deployment, and review native artifacts before installation.Versions through 0.1.7 have a critical path-traversal vulnerability. Use 0.1.8 or later, prefer stdio, restrict workbook paths, avoid public remote listeners, and keep recoverable backups.
Evidence date
Editorial review2026-08-142026-08-13
Candidate evidence2026-08-14T18:46:26.000Z2026-08-14T18:46:26.000Z

Popularity, maintenance, fit, permissions, and client support are independent evidence fields.

Read the evidence method →
Compare MCPs | MCP100 Index