Atlas / MCP servers / officemcp / Office

OfficeBLOCK

mcp/officemcp/office-1

The MCP server for AI like to automate Microsoft office applications like Word, Excel, Outlook, PowerPoint, Access, OneNote, Publisher, Visio, Project and also WPS .

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
13 12r · 1w · 0d
Transport
sse
License
—
Stars
121
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The most seeable and free way to control Microsof applications by AI model.

[](https://pypi.org/project/fastmcp)

OfficeMCP

OfficeMCP server is designed for AI to automate Microsoft Office Applications (Word, Excel, PowerPoint, Access, OneNote, Visio, Project, WPS.word, Wps.powerpoint, wps.excel etc.) by COM interface in Windows OS. Not working on Linux/MacOS.

Warns

Please keep it in mind, as OfficeMCP not limit the usage of python. epeciall there's a tool RunPython(...) to execute python codes created by Ai model. But it is also the most wonderfull parts of OfficeMCP. we can't guarantee that your AI model will not do something bad to your computer. we don't take any responsibility.

System Requirements

  1. Windows system
  1. python 3.1 or above installed
  1. uv installed

open an shell window and run command

pip install uv

How to install OfficeMCP

There are two ways or two modes to install OfficeMCP (They also can be used in the same time):

1. Use OfficeMCP as stdio server:

  • One OfficeMCP server for one mcp client mode
  • Put following setting to MCP.json file for vscode or some proper place for other AI IDE:
{
"mcpServers": {
"OfficeMCP": {
"type": "stdio",
"command": "uvx",
"args": [
"officemcp"
]
}
}
}

2. Use OfficeMCP as sse server:

  • One OfficeMCP server for multi mcp client mode
  • You can change port and host as you like
  • This is recommended way to use OfficeMCP server.

step 1:

Run one command in shell or power shell:

uvx officemcp sse

the Mcp server url will be: "http://127.0.0.1:8888/sse" or "http://127.0.0.1:8888/sse" the default work folder is D:\@officemcp

or something like below

uvx officemcp sse --port 7777 --host 127.0.0.8 --folder D:\myfold
Read from source at commit 41f4c67f6c86OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add officemcp -- uvx officemcp
claude-desktop
{
  "mcpServers": {
    "officemcp": {
      "command": "uvx",
      "args": [
        "officemcp"
      ]
    }
  }
}
03

Exposed tools (13)

12 read · 1 write · 0 destructive.

ToolRiskDescription
AvailableAppsreadGet Microsoft Office applications availability.
BeepreadBeep the computer. frequency range is 37 to 32767, duration range is 0 to 65535.
DemonstratereadDemonstrate for you to see some functions in this OfficeMCP server.
DownloadImagewriteDownload an image from the given URL and save it to the specified path.
IsAppAvailablereadCheck if the specified application is installed.
IsFileExistsreadreturn Officer.IsFileExists(sub_file_path)
LaunchreadLaunch an new microsoft excel application or use the existed one.
QuitreadQuit the microsoft excel application.
RootFolderreadreturn the default folder for this OfficeMCP server.
RunningAppsreadGet Microsoft Office applications availability.
ScreenShotreadLaunch an new microsoft excel application or use the existed one.
SpeakreadSpeak the text. volume range is 0-100, rate range is -10 to 10.
VisiblereadCheck if the microsoft excel application is visible.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (8)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/officemcp/OfficeMCP.py:133
exec(code, namespace)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
dist/officemcp-1.0.5-py3-none-any.whl
officemcp-1.0.5-py3-none-any.whl
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
dist/officemcp-1.0.5.tar.gz
officemcp-1.0.5.tar.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
sse
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:60
the Mcp server url will be:  "http://127.0.0.1:8888/sse"  or  "http://127.0.0.1:8888/sse"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:67
"url" will be : "http://127.0.0.8:7777/sse"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:75
"url": "http://127.0.0.1:8888/sse"

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha 41f4c67f6c86full audit observations/trust-audit/mcp-server/officemcp__office-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0741f4c67f6c86BLOCKD69first audit
06

Questions

What is the Office MCP server?

The MCP server for AI like to automate Microsoft office applications like Word, Excel, Outlook, PowerPoint, Access, OneNote, Publisher, Visio, Project and also WPS .

What tools does Office expose?

13 in total: 12 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Office safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Office need?

No credential environment variables were found in its source, so it appears to need none.

How does Office run?

It speaks sse, so it runs as a service you connect to over the network. It is published on PyPI as officemcp.

How current is this page?

The grade is for one exact copy of the source (41f4c67f6c86), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement