
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
tablebridge
Advanced tools
An MCP server that turns a folder of CSV / Parquet / JSON files into one SQL-queryable source for your AI agent.
Turn a folder of CSV / Parquet / JSON files into one SQL-queryable source for your AI agent.
Small businesses don't have a data warehouse — they have a folder full of exports: customers.csv, last month's orders.xlsx, a regions.json someone emailed over. tablebridge is an MCP server that points DuckDB at that folder, exposes each file as a SQL table, and lets your agent run read-only SQL — including JOINs across files — to answer questions over all of them at once. Scattered spreadsheets become one queryable source of truth.
It's read-only and sandboxed: files are loaded into an in-memory database, the data directory is the only thing it can see, and queries are validated so an agent can't write, escape to other paths, or call raw file functions.
orders.csv to customers.csv to regions.json in a single query — no ETL, no database to stand up.list_sources → describe → query is a natural flow the agent can follow on its own.mcp, duckdb), fully typed and tested.uvx tablebridge # run directly
# or
pip install tablebridge # then run: tablebridge
TABLEBRIDGE_DATA_DIR=/path/to/your/data claude mcp add tablebridge -- uvx tablebridge
{
"mcpServers": {
"tablebridge": {
"command": "uvx",
"args": ["tablebridge"],
"env": { "TABLEBRIDGE_DATA_DIR": "/path/to/your/data" }
}
}
}
A Dockerfile is included. The server speaks MCP over stdio. Mount the
folder you want to query at /data (read-only is fine) and run interactively (-i):
docker build -t tablebridge .
docker run --rm -i -v /path/to/your/data:/data:ro tablebridge
| Tool | Description |
|---|---|
list_sources | List the tables (one per data file) with column counts — start here |
describe | A table's columns and types |
preview | First N rows of a table |
query | Run read-only SQL (DuckDB dialect) across the tables, JOINs included |
refresh | Re-scan the data directory for added/changed files |
server_info | Effective config (data dir, row cap, supported formats) |
With a folder containing customers.csv, orders.csv, and regions.json:
You: Who are my top 3 customers by total spend, and what region are they in?
Agent: (calls
list_sources, thenquery)SELECT c.name, r.region, SUM(o.total) AS spend FROM customers c JOIN orders o ON o.customer_id = c.id JOIN regions r ON r.customer_id = c.id GROUP BY c.name, r.region ORDER BY spend DESC LIMIT 3;
| Variable | Default | Description |
|---|---|---|
TABLEBRIDGE_DATA_DIR | . | Directory of files to expose (the sandbox boundary) |
TABLEBRIDGE_MAX_ROWS | 1000 | Max rows returned per query/preview |
TABLEBRIDGE_RECURSIVE | 1 | Scan subdirectories too |
Supported formats: .csv, .tsv, .parquet, .json, .ndjson.
TABLEBRIDGE_DATA_DIR — only files under it are loaded.git clone https://github.com/Michael-WhiteCapData/tablebridge-mcp
cd tablebridge-mcp
uv pip install -e ".[dev]"
ruff check .
pytest # uses real DuckDB over temp files
See CONTRIBUTING.md.
MIT © Michael Tierney
FAQs
An MCP server that turns a folder of CSV / Parquet / JSON files into one SQL-queryable source for your AI agent.
We found that tablebridge demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.