OfficeBLOCK
The MCP server for AI like to automate Microsoft office applications like Word, Excel, Outlook, PowerPoint, Access, OneNote, Publisher, Visio, Project and also WPS .
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The most seeable and free way to control Microsof applications by AI model.
[](https://pypi.org/project/fastmcp)
OfficeMCP
OfficeMCP server is designed for AI to automate Microsoft Office Applications (Word, Excel, PowerPoint, Access, OneNote, Visio, Project, WPS.word, Wps.powerpoint, wps.excel etc.) by COM interface in Windows OS. Not working on Linux/MacOS.
Warns
Please keep it in mind, as OfficeMCP not limit the usage of python. epeciall there's a tool RunPython(...) to execute python codes created by Ai model. But it is also the most wonderfull parts of OfficeMCP. we can't guarantee that your AI model will not do something bad to your computer. we don't take any responsibility.
System Requirements
- Windows system
- python 3.1 or above installed
- uv installed
open an shell window and run command
pip install uv
How to install OfficeMCP
There are two ways or two modes to install OfficeMCP (They also can be used in the same time):
1. Use OfficeMCP as stdio server:
- One OfficeMCP server for one mcp client mode
- Put following setting to MCP.json file for vscode or some proper place for other AI IDE:
{
"mcpServers": {
"OfficeMCP": {
"type": "stdio",
"command": "uvx",
"args": [
"officemcp"
]
}
}
}2. Use OfficeMCP as sse server:
- One OfficeMCP server for multi mcp client mode
- You can change port and host as you like
- This is recommended way to use OfficeMCP server.
step 1:
Run one command in shell or power shell:
uvx officemcp sse
the Mcp server url will be: "http://127.0.0.1:8888/sse" or "http://127.0.0.1:8888/sse" the default work folder is D:\@officemcp
or something like below
uvx officemcp sse --port 7777 --host 127.0.0.8 --folder D:\myfold
41f4c67f6c86OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add officemcp -- uvx officemcp
{
"mcpServers": {
"officemcp": {
"command": "uvx",
"args": [
"officemcp"
]
}
}
}Exposed tools (13)
12 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
AvailableApps | read | Get Microsoft Office applications availability. |
Beep | read | Beep the computer. frequency range is 37 to 32767, duration range is 0 to 65535. |
Demonstrate | read | Demonstrate for you to see some functions in this OfficeMCP server. |
DownloadImage | write | Download an image from the given URL and save it to the specified path. |
IsAppAvailable | read | Check if the specified application is installed. |
IsFileExists | read | return Officer.IsFileExists(sub_file_path) |
Launch | read | Launch an new microsoft excel application or use the existed one. |
Quit | read | Quit the microsoft excel application. |
RootFolder | read | return the default folder for this OfficeMCP server. |
RunningApps | read | Get Microsoft Office applications availability. |
ScreenShot | read | Launch an new microsoft excel application or use the existed one. |
Speak | read | Speak the text. volume range is 0-100, rate range is -10 to 10. |
Visible | read | Check if the microsoft excel application is visible. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (8)
exec(code, namespace)
officemcp-1.0.5-py3-none-any.whl
officemcp-1.0.5.tar.gz
sse
the Mcp server url will be: "http://127.0.0.1:8888/sse" or "http://127.0.0.1:8888/sse"
"url" will be : "http://127.0.0.8:7777/sse"
"url": "http://127.0.0.1:8888/sse"
Gates applied: no_behavioural_pass, no_license.
41f4c67f6c86full audit observations/trust-audit/mcp-server/officemcp__office-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 41f4c67f6c86 | BLOCK | D | 69 | first audit |
Questions
What is the Office MCP server?
The MCP server for AI like to automate Microsoft office applications like Word, Excel, Outlook, PowerPoint, Access, OneNote, Publisher, Visio, Project and also WPS .
What tools does Office expose?
13 in total: 12 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Office safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Office need?
No credential environment variables were found in its source, so it appears to need none.
How does Office run?
It speaks sse, so it runs as a service you connect to over the network. It is published on PyPI as officemcp.
How current is this page?
The grade is for one exact copy of the source (41f4c67f6c86), read on 2026-10-07. The repository is watched and re-audited when it changes.