Atlas / MCP servers / meterlong / MCP-Doc

MCP-DocSAFE

mcp/meterlong/mcp-doc

A powerful Word document processing service based on FastMCP, enabling AI assistants to create, edit, and manage docx files with full formatting support. Preserves original styles when editing content. 基于FastMCP的强大Word文档处理服务,使AI助手能够创建、编辑和管理docx文件,支持完整的格式设置功能。在编辑内容时能够保留原始样式和格式,实现精确的文档操作。

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
23 7r · 13w · 3d
Transport
—
License
—
Stars
190
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 中文

[](https://smithery.ai/server/@MeterLong/mcp-doc)

A Docx document processing service based on the FastMCP library, supporting the creation, editing, and management of Word documents using AI assistants in Cursor.

Features

  • Complete Document Operations: Support for creating, opening, saving documents, as well as adding, editing, and deleting content
  • Formatting: Support for setting fonts, colors, sizes, alignment, and other formatting options
  • Table Processing: Support for creating, editing, merging, and splitting table cells
  • Image Insertion: Support for inserting images and setting their sizes
  • Layout Control: Support for setting page margins, adding page breaks, and other layout elements
  • Query Functions: Support for retrieving document information, paragraph content, and table data
  • Convenient Editing: Support for find and replace functionality
  • Section Editing: Support for replacing content in specific sections while preserving original formatting and styles

Installation Dependencies

Ensure Python 3.10+ is installed, then install the following dependencies:

pip3 install python-docx mcp

Usage

Using as an MCP Service in Cursor

  1. Open Cursor and go to Settings
  2. Find the Features > MCP Servers section
  3. Click Add new MCP server
  4. Fill in the following information:
  5. Name: MCP_DOCX
  6. Type: Command
  7. Command: python3 /path/to/MCP_dox/server.py (replace with the actual path to your server.py)
  8. Click Add to add the service

After adding, you can use natural language to operate Word documents in Cursor's AI assistant, for example:

  • "Create a new Word document and save it to the desktop"
  • "Add a level 3 heading"
  • "Insert a 3x4 table and fill it with data"
  • "Set the second paragraph to bold and center-aligned"

Supported Operations

The servic

Read from source at commit d7164aa86659OBSERVED · 2026-10-06
02

Exposed tools (23)

7 read · 13 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_headingwrite
add_page_breakwrite
add_paragraphwrite
add_tablewrite
add_table_rowwrite
create_documentwrite
create_document_copywrite
delete_paragraphdestructive
delete_table_rowdestructive
delete_textdestructive
edit_section_by_keywordwrite
edit_table_cellwrite
find_and_replaceread
get_document_inforead
merge_table_cellswrite
open_documentread
replace_sectionread
save_as_documentwrite
save_documentwrite
search_and_replaceread
search_textread
set_page_marginswrite
split_tableread
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_paragraph, delete_table_row, delete_text
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-06 · audit v0.4.1 · source sha d7164aa86659full audit observations/trust-audit/mcp-server/meterlong__mcp-doc.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06d7164aa86659SAFEB89first audit
05

Questions

What is the MCP-Doc MCP server?

A powerful Word document processing service based on FastMCP, enabling AI assistants to create, edit, and manage docx files with full formatting support. Preserves original styles when editing content. 基于FastMCP的强大Word文档处理服务,使AI助手能够创建、编辑和管理docx文件,支持完整的格式设置功能。在编辑内容时能够保留原始样式和格式,实现精确的文档操作。

What tools does MCP-Doc expose?

23 in total: 7 read-only, 13 that write, and 3 that can delete or overwrite (delete_paragraph, delete_table_row, delete_text). Every one is listed on this page with its risk.

Is MCP-Doc safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does MCP-Doc need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (d7164aa86659), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement