HwpSAFE
mcp for handling hwp
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/jkf87-hwp-mcp)
[](https://github.com/jkf87/hwp-mcp)
HWP-MCP는 한글 워드 프로세서(HWP)를 Claude와 같은 AI 모델이 제어할 수 있도록 해주는 Model Context Protocol(MCP) 서버입니다. 이 프로젝트는 한글 문서를 자동으로 생성, 편집, 조작하는 기능을 AI에게 제공합니다.
주요 기능
- 문서 생성 및 관리: 새 문서 생성, 열기, 저장 기능
- 텍스트 편집: 텍스트 삽입, 글꼴 설정, 단락 추가
- 테이블 작업: 테이블 생성, 데이터 채우기, 셀 내용 설정
- 완성된 문서 생성: 템플릿 기반 보고서 및 편지 자동 생성
- 일괄 작업: 여러 작업을 한 번에 실행하는 배치 기능
시스템 요구사항
- Windows 운영체제
- 한글(HWP) 프로그램 설치
- Python 3.10 이상 (
mcp패키지 요구사항) - 필수 Python 패키지 (requirements.txt 참조)
macOS/Linux 또는 한글이 설치되지 않은 환경에서도 서버는 실행되며, 이 경우 hwp_read_file(HWP 파일 읽기)만 사용할 수 있습니다.설치 방법
- 저장소 클론:
git clone https://github.com/jkf87/hwp-mcp.git cd hwp-mcp
- 의존성 설치:
pip install -r requirements.txt
- (선택사항) MCP 패키지 설치:
pip install "mcp<2"
사용 방법
Claude와 함께 사용하기
Claude 데스크톱 설정 파일에 다음과 같이 HWP-MCP 서버를 등록하세요:
{
"mcpServers": {
"hwp": {
"command": "python",
"args": ["경로/hwp-mcp/hwp_mcp_stdio_server.py"]
}
}
}주요 기능 예시
HWP 파일 읽기 (한글 프로그램 불필요, 모든 OS)
hwp_read_file("경로/문서.hwp") # 본문 텍스트 반환, 표는 Markdown 표로 변환새 문서 생성
hwp_create()
텍스트 삽입
hwp_insert_text("원하는 텍스트를 입력하세요.")테이블 생성 및 데이터 입력
# 테이블 생성 hwp_insert_table(rows=5, cols=2) # 테이블에 데이터 채우기 hwp_fill_table_with_data([ ["월", "판매량"], ["1월", "120"], ["2월", "150"], ["3월", "180"], ["4월", "200"] ], has_header=True) # 표에 연속된 숫자 채우기 hwp_fill_column_numbers(start=1, end=10, column=1, from_first_cell=True)
문서 저장
hwp_save("경로/문서명.hwp")일괄 작업 예시
hwp_batch_operations([
{"operation": "hwp_create"},
{"operation": "hwp_insert_text", "params": {"text": "제목"}},
{"operation": "hwp_set_font", "params"3423edbfef16OBSERVED · 2026-10-06Exposed tools (31)
22 read · 9 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
hwp_batch_operations | read | |
hwp_close_all_documents | read | |
hwp_close_document | read | |
hwp_close_window | read | |
hwp_create | write | Create a new HWP document. |
hwp_create_complete_document | write | |
hwp_create_document_from_text | write | |
hwp_create_table_with_data | write | |
hwp_fill_cells | read | |
hwp_fill_column_numbers | read | |
hwp_fill_table_with_data | read | |
hwp_find_and_show_cell | read | |
hwp_find_text | read | |
hwp_get_text | read | Get the text content of the current document. |
hwp_insert_paragraph | write | Insert a new paragraph. |
hwp_insert_table | write | Insert a table at the current cursor position. |
hwp_insert_text | write | Insert text at the current cursor position. |
hwp_list_tabs | read | |
hwp_list_windows | read | |
hwp_navigate | read | |
hwp_open | read | Open an existing HWP document. |
hwp_ping_pong | read | |
hwp_read_file | read | |
hwp_redo | read | |
hwp_replace_text | read | |
hwp_save | write | Save the current HWP document. |
hwp_set_font | write | Set font properties for selected text. |
hwp_switch_tab | read | |
hwp_switch_window | read | |
hwp_table_view | read | |
hwp_undo | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
FilePathCheckerModuleExample.dll
os.remove(temp_path)
mcp, olefile, pytest, pytest-cov
Gates applied: no_behavioural_pass, no_license.
3423edbfef16full audit observations/trust-audit/mcp-server/jkf87__hwp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 3423edbfef16 | SAFE | B | 89 | first audit |
Questions
What is the Hwp MCP server?
mcp for handling hwp
What tools does Hwp expose?
31 in total: 22 read-only, 9 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Hwp safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Hwp need?
No credential environment variables were found in its source, so it appears to need none.
How does Hwp run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (3423edbfef16), read on 2026-10-06. The repository is watched and re-audited when it changes.