Atlas / MCP servers / dayoooun / HWPX

HWPXCAUTION

mcp/dayoooun/hwpx

한글 문서(HWPX)를 읽고 쓰는 MCP 서버 — 125개 도구. npm: @kimdayoun/hwpx-mcp

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
118 62r · 46w · 10d
Transport
stdio
License
MIT
Stars
34
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/Dayoooun/hwpx-mcp) [](https://github.com/mjyoo2/hwp-extension)

🚀 Original 프로젝트를 Fork하여 안정성과 기능을 대폭 개선한 버전입니다.

AI 도구(Claude 등)와 연동하여 한글(HWPX) 문서를 자동으로 편집할 수 있는 MCP(Model Context Protocol) 서버입니다.

🌍 Cross-Platform Support

모든 운영체제에서 작동합니다!

왜 가능한가요? HWPX 파일은 ZIP + XML 구조입니다. 한글 프로그램 없이도 Node.js만으로 완벽하게 읽고 쓸 수 있습니다. *LibreOffice는 HWPX를 제한적으로 지원합니다. 완벽한 호환을 위해 한컴오피스 사용을 권장합니다.

✨ Enhanced Features (개선된 기능)

원본 프로젝트 대비 다음과 같은 핵심 문제들을 해결했습니다:

🔧 Critical Bug Fixes

🛠 Technical Improvements

  1. Atomic File Writing (원자적 파일 쓰기)
  2. 임시 파일 → ZIP 검증 → 원자적 이동
  3. 저장 중 오류 발생해도 원본 파일 보호
  1. Smart Lineseg Reset (스마트 줄 레이아웃 초기화)
  2. 텍스트 수정 시 lineseg 자동 초기화
  3. 한글 프로그램이 열 때 자동으로 줄바꿈 재계산
  4. 텍스트 겹침 현상 완전 해결
  1. Depth-based XML Parsing (깊이 기반 XML 파싱)
  2. 기존 lazy regex의 중첩 구조 오인식 문제 해결
  3. 복잡한 테이블(중첩 테이블, subList 등) 완벽 지원
  1. Complete Style Preservation (스타일 완전 보존)
  2. charPr, spacing 등 원본 스타일 100% 유지
  3. 불완전한 직렬화 로직 제거로 데이터 무결성 보장
  1. Safe Multi-Cell Updates (안전한 다중 셀 업데이트)
  2. 같은 행(row)의 여러 셀을 동시에 수정해도 안전
  3. 행별 그룹화 + 역순 처리로 인덱스 손상 방지

📦 Installation

1. MCP 서버 설치

git clone https://github.com/Dayoooun/hwpx-mcp.git
cd hwpx-mcp/mcp-server
npm install
npm run 
Read from source at commit 5d6917ca7195OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add hwpx-editor -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "hwpx-editor": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (118)

62 read · 46 write · 10 destructive. Blast radius: 10 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
analyze_xmlreadAnalyze document XML for issues like tag imbalance, malformed elements, etc. Useful for diagnosing save failures.
append_text_to_paragraphreadAppend text to an existing paragraph (HWPX only)
apply_stylewriteApply a named style to a paragraph (HWPX only)
batch_fill_tablereadFill multiple table cells at once from a 2D array. Perfect for: - Filling data tables from CSV/JSON - Batch updating table content - Template form filling Example: batch_fill_table({ data: [ [
batch_replacereadPerform multiple text replacements at once (HWPX only)
close_documentreadClose an open document
copy_paragraphreadCopy a paragraph to another location (HWPX only)
copy_tablereadCopy a table to another location (HWPX only). Preserves original and generates new IDs for the copy. Uses strict validation.
create_documentwriteCreate a new empty HWPX document. Pass file_path to fix where save_document will write it; otherwise you must pass output_path to save_document.
delete_imagedestructiveDelete an image from the document (HWPX only)
delete_memodestructiveDelete a memo/comment (HWPX only)
delete_paragraphdestructiveDelete a paragraph (HWPX only)
delete_sectiondestructiveDelete a section (HWPX only)
delete_tabledestructiveDelete an entire table from the document (HWPX only)
delete_table_columndestructiveDelete a column from a table (HWPX only)
delete_table_rowdestructiveDelete a row from a table. If the table has only 1 row, deletes the entire table (HWPX only)
export_to_htmlreadExport document to HTML file
export_to_textreadExport document to plain text file
fill_by_pathread⭐ RECOMMENDED for template work! Fill multiple cells using path-based addressing. jkf87-style path format:
find_cell_by_labelread🔍 Find table cells by label text and get the adjacent cell position. Perfect for Korean documents with
find_empty_tablesreadFind tables that are empty or contain only placeholder text (dashes, bullets, numbers only)
find_insert_position_after_headerwriteFind the right insertion position after text. Searches both independent paragraphs AND table cell contents by default. IMPORTANT - Check
find_insert_position_after_tablewriteFind the right insertion position AFTER a specific table (OUTSIDE the table). Returns section_index and insert_after value for use with insert_image/render_mermaid. NOTE: This inserts AFTER the table, not inside it. To insert an image INSIDE a table cell, use insert_image_in_cell directly.
find_paragraph_by_textreadFind paragraphs containing specific text. Returns element indices with surrounding context.
find_table_by_headerreadFind tables by their header text (partial match, case-insensitive)
get_bookmarksreadGet all bookmarks in the document
get_cell_contextreadGet surrounding cells
get_char_shapesreadGet all character shape definitions
get_chunk_at_offsetread📌 Get the chunk containing a specific character offset. Use after finding a position in the index to get the full chunk context.
get_chunk_contextread📄 Get surrounding chunks for expanded context around a specific chunk. After finding a relevant chunk with search_chunks, use this to get additional context by retrieving chunks before and after the target chunk.
get_column_defreadGet column definition for a section
get_document_metadatareadGet document metadata (title, author, dates, etc.)
get_document_outlinereadGet document outline - hierarchical structure showing sections, headings, and tables with their positions
get_document_structurereadGet document structure (sections, paragraphs, tables, images count)
get_document_textreadGet all text content from the document
get_element_index_for_tablereadConvert a global table index to element index in its section. Use this to find the right position for inserting content near a table.
get_endnotesreadGet all endnotes in the document
get_equationsreadGet all equations in the document
get_footerreadGet footer content for a section
get_footnotesreadGet all footnotes in the document
get_hanging_indentreadGet hanging indent value for a paragraph
get_headerreadGet header content for a section
get_hyperlinksreadGet all hyperlinks in the document
get_imageswriteGet all images in the document. For inserting images, see insert_image or insert_image_in_cell.
get_insert_contextwriteGet context around an element index to verify insertion point. Shows elements before/after.
get_memosreadGet all memos/comments in the document
get_page_settingsreadGet page settings (paper size, margins)
get_para_shapesreadGet all paragraph shape definitions
get_paragraphreadGet a specific paragraph with full details
get_paragraph_stylereadGet paragraph formatting
get_paragraphsreadGet paragraphs from the document with their text and styles
get_position_indexread📍 Get cached position index (builds if not available). Returns all indexed elements. Use search_position_index for filtered queries.
get_raw_section_xmlread⚠️ DEPRECATED: Use get_section_xml instead. This tool is kept for backward compatibility only.
get_section_xmlreadGet raw XML content of a section. Useful for AI-based document manipulation. Returns the complete section XML that can be modified and set back using set_section_xml.
get_sectionsreadGet all sections in the document
get_stylesreadGet all defined styles in the document
get_tablereadGet a specific table with full data
get_table_as_csvreadExport table content as CSV format
get_table_cellreadGet content of a specific table cell
get_table_cell_hanging_indentreadGet hanging indent value for a paragraph inside a table cell
get_tablesreadGet all tables from the document
get_tables_by_sectionreadGet all tables within a specific section
get_tables_summaryreadGet summary of multiple tables by index range. Returns compact info: header, size, empty status, and content preview.
get_text_stylereadGet character formatting of a paragraph
get_tool_guidewrite🎯 START HERE! Get recommended tools for your task. Call this FIRST to understand which tools to use. Available workflows: -
get_word_countreadGet word and character count statistics
insert_bookmarkwriteInsert a bookmark at a specific location (HWPX only)
insert_ellipsewriteInsert an ellipse drawing object (HWPX only)
insert_endnotewriteInsert an endnote at a specific location (HWPX only)
insert_equationwriteInsert an equation (HWPX only)
insert_footnotewriteInsert a footnote at a specific location (HWPX only)
insert_hyperlinkwriteInsert a hyperlink in a paragraph (HWPX only)
insert_imagewriteInsert an image into the document (HWPX only)
insert_image_in_cellwrite📍 Insert an image INSIDE a specific table cell (HWPX only). The image appears inline within the cell content. ⚠️ IMPORTANT: Use this tool (NOT insert_image) when inserting images into table cells! When to use: 1. find_insert_position_after_header returned found_in=
insert_linewriteInsert a line drawing object (HWPX only)
insert_memowriteInsert a memo/comment (HWPX only)
insert_nested_tablewriteInsert a table inside a table cell (nested table, HWPX only)
insert_paragraphwriteInsert a new paragraph (HWPX only). Automatically applies hanging indent if text contains a marker like
insert_rectwriteInsert a rectangle drawing object (HWPX only)
insert_sectionwriteInsert a new section (HWPX only)
insert_tablewriteInsert a new table (HWPX only)
insert_table_columnwriteInsert a new column in a table (HWPX only)
insert_table_rowwriteInsert a new row in a table (HWPX only)
invalidate_reading_cachedestructive🔄 Clear cached chunks and position index. Call this after modifying the document to ensure fresh data on next read operation.
list_open_documentsreadList all currently open documents
merge_cellswriteMerge multiple table cells into a single cell (HWPX only). The top-left cell becomes the master cell with increased colSpan/rowSpan.
move_paragraphwriteMove a paragraph to another location (HWPX only)
move_tablewriteMove a table to another location (HWPX only). Uses XML-based approach for accurate structure preservation with strict validation.
open_documentreadOpen an HWPX or HWP document for reading and editing
redoreadRedo the last undone change(s). Supports multiple redo with count parameter.
remove_hanging_indentdestructiveRemove hanging indent from a paragraph (HWPX only)
remove_table_cell_hanging_indentdestructiveRemove hanging indent from a paragraph inside a table cell (HWPX only)
render_mermaid_in_cellwrite📍 Render a Mermaid diagram and insert it INSIDE a specific table cell (HWPX only). Uses mermaid.ink API. ⚠️ IMPORTANT: Use this tool (NOT render_mermaid) when inserting diagrams into table cells! When to use: 1. find_insert_position_after_header returned found_in=
repair_xmlreadAttempt to repair XML issues in a section. Removes orphan closing tags and fixes table structure.
replace_textreadFind and replace text throughout the ENTIRE document (HWPX only). ⚠️ This searches ALL paragraphs and table cells in the document. When to use: - Bulk replacement (e.g., change
replace_text_in_cellreadReplace text within a specific table cell (HWPX only). More targeted than replace_text.
save_documentwriteSave the document (HWPX only). Supports backup creation and integrity verification.
search_position_indexread🔎 Search position index by text and/or element type. Filter the position index to find specific headings, paragraphs, or tables by their text content.
search_textreadSearch for text in the document (includes table cells by default)
set_auto_hanging_indentwriteAutomatically set hanging indent based on detected marker in paragraph text (HWPX only). Detects markers like
set_cell_propertieswriteSet table cell properties (HWPX only)
set_column_defwriteSet column definition for a section (HWPX only)
set_document_metadatawriteSet document metadata (HWPX only)
set_footerwriteSet footer content for a section (HWPX only)
set_hanging_indentwriteSet hanging indent with MANUAL pt value (HWPX only). 💡 In most cases, use set_auto_hanging_indent instead - it automatically detects markers and calculates the correct indent. Use this manual version only when: - You need a specific indent value (e.g., exactly 20pt) - Auto-detection doesn
set_headerwriteSet header content for a section (HWPX only)
set_page_settingswriteSet page settings (HWPX only)
set_paragraph_stylewriteApply paragraph formatting (HWPX only)
set_raw_section_xmlwrite⚠️ DEPRECATED: Use set_section_xml instead. This tool is kept for backward compatibility only.
set_section_xmlwriteSet (replace) raw XML content of a section (HWPX only). WARNING: This completely replaces the section XML. The XML must be valid HWPML format. Use get_section_xml first to get the current structure, modify it, then set it back.
set_table_cell_auto_hanging_indentwriteAutomatically set hanging indent on a paragraph inside a table cell based on detected marker (HWPX only). Detects markers like
set_table_cell_hanging_indentwriteSet hanging indent on a paragraph inside a table cell (HWPX only). Hanging indent pulls the first line left while indenting the rest of the lines.
set_text_stylewriteApply character formatting to a paragraph run (HWPX only)
split_cellreadSplit a merged table cell back into individual cells (HWPX only). Only works on cells with colSpan > 1 or rowSpan > 1.
undoreadUndo the last change(s). Supports multiple undo with count parameter.
update_image_sizewriteUpdate the size of an existing image (HWPX only)
update_paragraph_textwriteUpdate paragraph text content (HWPX only)
update_table_cellwriteUpdate content of a table cell (HWPX only)
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (2 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (11)

MEDIUMInventory / provenance · inv.binary · CWE-1104
mcp-server/test-output/text-duplication-test.hwpx.bak
text-duplication-test.hwpx.bak
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
test-output/test1.hwpx.bak
test1.hwpx.bak
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_image, delete_memo, delete_paragraph, delete_section, delete_table, delete_table_column, delete_table_row, invalidate_reading_cache, remove_hanging_indent, remove_table_cell_hanging_indent
Why it matters. 10 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.vscodeignore
.vscodeignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp-server/tests/helpers/hwpx.ts:10
import { HwpxDocument } from '../../src/HwpxDocument';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp-server/tests/helpers/mcp-client.ts:53
: spawn(process.env.HWPX_MCP_NODE || process.execPath, [path.resolve(__dirname, '../../dist/index.js')], { cwd, stdio: ['pipe', 'pipe', 'pipe'] });
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp-server/tests/module/hancom-shapes.test.ts:9
import { HwpxDocument } from '../../src/HwpxDocument';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp-server/tests/module/hancom-shapes.test.ts:10
import { error, findMissingArgs } from '../../src/ToolResult';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp-server/tests/regression/review-2026-09-24.test.ts:10
import { HwpxDocument } from '../../src/HwpxDocument';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
mcp-server/package.json
@modelcontextprotocol/sdk, hwp.js, jszip, pako, saxes, @types/node, @types/pako, ts-node
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, hwp.js, jszip, pako, @types/node, @types/pako, @types/vscode, @vscode/vsce
Why it matters. 11 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 5d6917ca7195full audit observations/trust-audit/mcp-server/dayoooun__hwpx.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-085d6917ca7195CAUTIONB89first audit
06

Questions

What is the HWPX MCP server?

한글 문서(HWPX)를 읽고 쓰는 MCP 서버 — 125개 도구. npm: @kimdayoun/hwpx-mcp

What tools does HWPX expose?

118 in total: 62 read-only, 46 that write, and 10 that can delete or overwrite (delete_image, delete_memo, delete_paragraph, delete_section, delete_table). Every one is listed on this page with its risk.

Is HWPX safe to connect to an agent?

With care. The audit graded it B (89/100) and found 11 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 10 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does HWPX need?

No credential environment variables were found in its source, so it appears to need none.

How does HWPX run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as hwpx-editor at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (5d6917ca7195), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement