Atlas / MCP servers / securityronin / Docx

DocxSAFE

mcp/securityronin/docx-2

MCP server for reading and editing Word (.docx) documents with track changes, comments, footnotes, and structural validation

Verdict
SAFE
Grade
B
Trust score
85 /100
Exposed tools
200 72r · 119w · 27d
Transport
—
License
MIT
Stars
58
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://pypi.org/project/docx-mcp-server/) [](https://pypi.org/project/docx-mcp-server/) [](https://opensource.org/licenses/MIT) [](https://github.com/SecurityRonin/docx-mcp/actions/workflows/ci.yml) [](https://github.com/SecurityRonin/docx-mcp) [](https://github.com/sponsors/h4x0r) [](https://safeskill.dev/scan/securityronin-docx-mcp)

Give your AI coding agent the ability to create, read, and edit Word documents. Edits appear as tracked changes in Microsoft Word — red strikethrough for deletions, green underline for insertions — and after any revision session your agent can produce an email-ready change log listing every insertion, deletion, and replacement. Or compare two separate files to get the same output automatically.

Who This Is For

Professionals who produce Word deliverables and want their AI agent to handle the document work directly:

  • Legal — contract review with tracked redlines, batch clause replacement across templates, comment annotations explaining each change, footnote management
  • Security & Penetration Testing — generate pentest reports from markdown findings, merge appendices from multiple engagements, add executive-summary comments, remove DRAFT watermarks before delive
Read from source at commit 3ab2b904890bOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add docx-mcp-server -- uvx docx-mcp-server
claude-desktop
{
  "mcpServers": {
    "docx-mcp-server": {
      "command": "uvx",
      "args": [
        "docx-mcp-server"
      ]
    }
  }
}
03

Exposed tools (200)

72 read · 119 write · 27 destructive. Blast radius: 27 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
accept_all_changeswriteAccept all tracked changes in document order.
accept_changereadAccept a single tracked change by its change_id.
accept_changesdestructiveAccept tracked changes — keep insertions, remove deletions. Empty author = all.
add_bookmarkwriteAdd a named bookmark wrapping the specified paragraph.
add_column_to_tablewriteAdd a new column to every row of a table. First row gets header_text.
add_commentwriteAdd a comment anchored to a paragraph.
add_content_controlwriteWrap a paragraph in an SDT content control.
add_cross_referencewriteAdd a cross-reference link from one paragraph to another.
add_endnotewriteAdd an endnote to a paragraph.
add_equationwriteInsert a LaTeX equation as OMML. Requires: pip install latex2mathml.
add_fieldwriteInsert a Word field at end of paragraph.
add_footnotewriteAdd a footnote to a paragraph. url, if provided, is rendered as a hotlink.
add_footnote_refwriteAdd a subsequent reference to an existing footnote without creating a new definition.
add_hyperlinkwriteAppend an external hyperlink at the end of a paragraph.
add_internal_linkwriteAppend an internal anchor hyperlink (w:anchor) at the end of a paragraph.
add_listwriteApply list formatting to paragraphs (bullet or numbered).
add_page_breakwriteInsert a page break after a paragraph.
add_section_breakwriteAdd a section break at a paragraph. break_type: nextPage/continuous/evenPage/oddPage.
add_tablewriteInsert a new table after a paragraph with tracked insertion.
add_table_rowwriteAdd a row to a table with tracked insertion. row_idx=-1 appends.
apply_style_to_rangewriteApply a style to a list of paragraphs by their paraIds.
audit_documentwriteRun a comprehensive structural audit of the document.
check_accessibilityreadScan the document for accessibility issues.
clear_run_formattingdestructiveRemove all character formatting from a run, causing it to inherit paragraph/style defaults.
close_documentreadClose a document and clean up temporary files.
compare_contractsreadClause-aware diff between the open contract and another .docx file.
compare_documentsreadDiff two DOCX files and produce a tracked-change document.
convert_to_pdfreadConvert the open document to PDF using LibreOffice headless.
copy_documentwriteSave a complete snapshot of the open document to a new path.
copy_stylereadDeep-copy an existing style under a new name.
copy_tablewriteDeep-copy a table and insert the copy immediately after the original.
create_documentwriteCreate a new blank .docx document (or from a .dotx template).
create_from_markdownwriteCreate a new .docx document from markdown content.
create_multilevel_listwriteCreate a multilevel list in numbering.xml. Each level dict: {num_fmt, lvl_text, indent, hanging, style?}.
create_stylewriteCreate a new style in the document.
csv_to_tablewriteInsert a table from CSV text.
delete_column_from_tabledestructiveDelete a column (0-based) from every row of a table.
delete_commentdestructiveDelete a comment and remove its range markers from the document.
delete_content_controldestructiveRemove an SDT content control wrapper, keeping its content in place.
delete_custom_propertydestructiveDelete a custom document property by name.
delete_endnotedestructiveDelete an endnote and its in-body reference.
delete_fielddestructiveRemove a complete complex field (begin through end runs) from the document.
delete_footerdestructiveDelete a footer by location: default, first, or even.
delete_footnotedestructiveDelete a footnote and its in-body reference.
delete_headerdestructiveDelete a header by location: default, first, or even.
delete_imagedestructiveRemove the drawing containing the image with the given rId from the document.
delete_paragraphdestructiveDelete the paragraph with the given paraId.
delete_section_breakdestructiveRemove a section break from a paragraph.
delete_styledestructiveDelete a style from the document.
delete_tabledestructiveDelete a table by index (0-based). Raises IndexError if out of range.
delete_table_rowdestructiveDelete a table row with tracked changes.
delete_textdestructiveDelete text from a paragraph.
demote_list_itemreadIncrease the list indentation level (ilvl) of a paragraph by 1, maximum 8.
diff_to_textreadCompare two separate DOCX files and produce a tracked-change DOCX plus a plain-text summary.
duplicate_table_rowwriteDeep-copy a table row and insert the copy immediately after it.
edit_header_footerwriteEdit text in a header or footer.
export_markdownreadExport the open document as Markdown.
export_session_scriptwriteWrite session operations as a Python replay script.
fill_templatereadFill SDT content controls from data dict. Keys match w:tag values.
find_replace_formattedreadFind all occurrences of a string and replace with formatted text.
flatten_documentdestructiveAccept all tracked changes and remove all revision markup.
generate_change_summaryreadSummarise tracked changes already present in the open document as an email-ready .txt.
generate_list_of_figureswriteInsert a List of Figures field (requires SEQ Figure captions).
generate_list_of_tableswriteInsert a List of Tables field (requires SEQ Table captions).
generate_privilege_logreadGenerate a privilege log DOCX from document metadata.
generate_redaction_logwriteWrite a DOCX table of all redactions made this session.
generate_tocreadGenerate a Table of Contents from document headings.
generate_tofwriteInsert a Table of Figures field block after the paragraph with para_id.
generate_totwriteInsert a Table of Tables field block after the paragraph with para_id.
get_alt_textreadGet the alt text and title for an image by 0-based index.
get_body_textreadReturn the full accepted-view text of the document.
get_bookmarked_textreadGet the text content within a named bookmark.
get_cell_textreadReturn text content of a specific cell.
get_commentsreadList all comments with their ID, author, date, and text.
get_content_controlreadReturn details of a single content control by its w:id.
get_content_controlsreadList all SDT content controls in the document.
get_custom_propertiesreadGet custom document properties from docProps/custom.xml.
get_document_inforeadGet overview stats: paragraph count, headings, footnotes, comments, images.
get_document_outlinereadReturn a flat list of headings as a document outline.
get_endnotesreadGet all endnotes with their ID and text content.
get_equationsreadReturn all equations in the document as OMML XML strings.
get_fieldreadReturn details of a single field by field_id.
get_footnotesreadList all footnotes with their ID and text content.
get_headers_footersreadGet all headers and footers with their text content.
get_headingsreadGet the document heading structure with levels, text, and paraIds.
get_imagesreadGet all embedded images with rId, filename, content type, and dimensions.
get_listsreadReturn all list definitions from numbering.xml.
get_paragraphreadGet the full text and style of a specific paragraph by its paraId.
get_paragraph_formatreadRead all formatting attributes of a paragraph.
get_propertiesreadGet core document properties (title, creator, subject, dates, revision).
get_reading_timereadEstimate reading time for the open document.
get_runsreadGet all runs in a paragraph with their formatting properties.
get_sectionsreadList all sections in the document with their properties.
get_session_logreadReturn all operations performed this session as replayable JSON.
get_statisticsreadReturn document statistics for the open document.
get_stylereadGet details of a single style by name or styleId (case-insensitive).
get_stylesreadGet all defined styles with ID, name, type, and base style.
get_tablereadGet structured info for a single table by zero-based index.
get_tablesreadGet all tables with row/column counts and cell text content.
get_theme_colorsreadReturn the named color slots from word/theme/theme1.xml.
get_tracked_changesreadReturn all pending tracked changes (insertions and deletions) as a JSON list.
get_word_countreadReturn the word count of the open document body.
insert_bar_chartwriteInsert a native bar chart (no Excel required).
insert_blockquotewriteInsert a blockquote paragraph after the given paragraph.
insert_captionwriteInsert a caption paragraph after the specified paragraph.
insert_code_blockwriteInsert a code-block paragraph after the given paragraph.
insert_date_fieldwriteInsert a DATE field at the end of a paragraph.
insert_floating_imagewriteInsert a floating (anchored) image. wrap: square|topbottom|none.
insert_if_fieldwriteInsert a Word IF conditional field at the end of a paragraph.
insert_imagewriteInsert an image into the document after a paragraph.
insert_line_chartwriteInsert a native line chart.
insert_merge_fieldwriteInsert a MERGEFIELD (mail merge) field at the end of a paragraph.
insert_page_number_fieldwriteInsert a PAGE field at the end of a paragraph.
insert_paragraphwriteInsert a new paragraph after the paragraph with the given paraId.
insert_pie_chartwriteInsert a native pie chart (single series, fixed 14x9 cm).
insert_sequence_fieldwriteInsert a SEQ (sequence) field for figure/table numbering.
insert_textwriteInsert text into a paragraph.
insert_text_boxwriteInsert an inline text box after the paragraph with para_id.
insert_watermarkwriteInsert a VML watermark into the document
list_bookmarksreadList all bookmarks in the document.
list_comment_threadsreadList all comment threads (root comments with their replies).
list_fieldsreadList all fields in the document with their codes and cached values.
list_hyperlinksreadList all hyperlinks in the document.
list_partsreadList all XML parts (files) in the open DOCX zip.
list_template_fieldsreadList all SDT template fields (tag, label, type) in the document.
lock_content_controlreadLock a content control to prevent editing.
merge_cellswriteMerge a rectangular range of cells. Horizontal: gridSpan. Vertical: vMerge.
merge_documentswriteMerge another DOCX document
merge_review_roundswriteMerge tracked changes from N reviewer copies into the open document.
modify_cellwriteModify a table cell.
open_documentreadOpen a .docx file for reading and editing.
promote_list_itemreadDecrease the list indentation level (ilvl) of a paragraph by 1, minimum 0.
read_partreadRead raw XML of any DOCX part (e.g.
redact_textdestructiveTrue redaction: remove text and replace with black rectangle. Use exact_text or pattern.
reject_all_changeswriteReject all tracked changes in document order.
reject_changereadReject a single tracked change by its change_id.
reject_changesdestructiveReject tracked changes — remove insertions, restore deleted text.
remove_bookmarkdestructiveRemove a bookmark by name (keeps paragraph content).
remove_hyperlinkdestructiveRemove a hyperlink wrapper, preserving the text runs inside.
remove_watermarkdestructiveRemove VML watermarks (e.g., DRAFT) from all document headers.
replace_textreadReplace text in a paragraph.
reply_to_commentreadReply to an existing comment (creates a threaded reply).
resolve_commentreadMark a comment as resolved (sets w15:done=
restart_numberingwriteRestart list numbering at a paragraph. Adds lvlOverride with startOverride.
sanitize_metadatawriteWrite a sanitized copy of the open document to output_path.
save_documentwriteSave all changes back to a .docx file.
scrub_piiread[EXPERIMENTAL] Detect and redact PII from the open document using Presidio + spaCy NER.
search_textreadSearch for text across the document body, footnotes, and comments.
set_alt_textwriteSet the alt text (and optionally title) on an image by 0-based index.
set_cell_shadingwriteSet background shading fill color on a table cell.
set_cell_vertical_alignmentwriteSet vertical alignment of a table cell: top, center, or bottom.
set_cell_widthwriteSet the width of a table cell in millimetres (stored as DXA).
set_character_positionwriteSet vertical character position (raised/lowered) for a specific run.
set_character_spacingwriteSet character spacing (tracking) for a specific run in a paragraph.
set_column_widthswriteSet column widths in cm. len(widths_cm) must match column count.
set_content_control_valuewriteUpdate the value/text of a content control by its tag.
set_custom_propertywriteSet (upsert) a custom document property.
set_different_first_pagewriteEnable or disable a different first-page header/footer for a section.
set_document_languagewriteSet the default document language.
set_document_protectionwriteSet document protection. edit: trackedChanges/comments/readOnly/forms/none.
set_formattingwriteApply character formatting to text with tracked-change markup.
set_header_rowwriteMark the first row as a repeating header row.
set_image_alt_textwriteSet accessibility alt text and title on an embedded image.
set_image_borderdestructiveSet or remove a border on an embedded image.
set_image_sizewriteResize an embedded image by updating its EMU extent attributes.
set_keep_lines_togetherwriteKeep all lines of this paragraph on the same page.
set_keep_with_nextwriteKeep this paragraph on the same page as the next paragraph.
set_line_spacingwriteSet line spacing and paragraph spacing.
set_odd_even_headerswriteEnable or disable different odd/even page headers globally.
set_page_break_beforedestructiveForce a page break before this paragraph.
set_page_marginswriteSet page margins from millimetre values.
set_page_orientationwriteSet page orientation, swapping width/height dimensions if needed.
set_page_sizewriteSet page size from millimetre values.
set_paragraph_borderwriteSet borders on one or more sides of a paragraph.
set_paragraph_indentationwriteSet indentation on a paragraph.
set_paragraph_shadingwriteSet background shading on a paragraph.
set_propertieswriteSet core document properties. Empty string = unchanged.
set_row_heightwriteSet row height in millimetres. rule: exact, atLeast, or auto.
set_run_colorwriteSet the font color of a specific run in a paragraph.
set_run_fontwriteSet the font of a specific run (zero-based index) in a paragraph.
set_run_highlightwriteSet highlight color of a specific run in a paragraph.
set_run_languagewriteSet the language on a run for spell-checking purposes.
set_run_sizewriteSet the font size of a specific run in a paragraph.
set_run_strikethroughwriteSet strikethrough on a specific run in a paragraph.
set_run_subscriptwriteSet subscript vertical alignment on a specific run in a paragraph.
set_run_superscriptwriteSet superscript vertical alignment on a specific run in a paragraph.
set_run_underlinewriteSet underline style on a specific run in a paragraph.
set_section_columnswriteSet the number of columns in a section.
set_section_propertieswriteModify section properties (page size, orientation, margins). 0/empty = unchanged.
set_table_alignmentwriteSet table alignment: left, center, or right.
set_table_borderswriteSet borders on all six sides of a table (top, bottom, left, right, insideH, insideV).
set_table_stylewriteApply a named table style (e.g. TableGrid, LightShading-Accent1) to a table.
set_text_casewriteSet text case transformation on a run.
set_theme_colorwriteUpdate a named color slot in the document theme.
set_track_changeswriteEnable or disable revision tracking in the document.
set_widow_controlwriteEnable widow/orphan control for this paragraph.
sort_tablereadSort the non-header rows of a table by the text content of a column.
split_documentreadSplit the open document into multiple DOCX files, one per heading section.
split_tablereadSplit a table into two tables at the given row index.
suppress_numberingdestructiveRemove list numbering from a paragraph by setting numId to 0.
04

Trust audit

SAFEgrade B · trust 85/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (23)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
accept_changes, clear_run_formatting, delete_column_from_table, delete_comment, delete_content_control, delete_custom_property, delete_endnote, delete_field, delete_footer, delete_footnote, delete_hea
Why it matters. 27 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/lo_chart.docx
lo_chart.docx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/lo_groupshape_sdt.docx
lo_groupshape_sdt.docx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/lo_sdt_content.docx
lo_sdt_content.docx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/lo_textbox.docx
lo_textbox.docx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/lo_toc_field.docx
lo_toc_field.docx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
tests/test_security_document.py:75
path = _make_zipslip_docx(tmp_path, "/etc/cron.d/evil")
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
tests/test_security_guards.py:85
InputGuard.output_path("/etc/passwd")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_fuzz_smoke.py:51
zf.writestr("../../evil.txt", "pwned")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_security_document.py:66
path = _make_zipslip_docx(tmp_path, "../../evil.txt")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_security_document.py:193
doc.save("../../etc/passwd.docx")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_security_document.py:209
doc.copy_document("../../etc/evil.docx")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_security_guards.py:75
InputGuard.output_path("../../etc/passwd.docx")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
sessions/2026-03-23-feature-expansion.md:2189
[tools: WebFetch http://103.203.175.90:81/fdScript/RootOfEBooks/E%20Book%20collection%20-%202026%20-%20B/RARE%20BOOKS/FACT%20Attribution%20Framework%20v1.0.pdf]
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
sessions/2026-03-23-feature-expansion.md:2193
[tools: Bash `curl -sL -o /tmp/FACT_Attribution_Framework_v1.0.pdf "http://103.203.175.90:8...`]
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
sessions/2026-03-23-feature-expansion.md:2485
>    - **Reading FACT Attribution Framework v1.0 PDF**: From `http://103.203.175.90:81/fdScript/RootOfEBooks/...` to support account-to-person attribution reasoning, with citation to `https://zenodo.o
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
sessions/2026-03-23-feature-expansion.md:2603
>    - "read http://103.203.175.90:81/fdScript/RootOfEBooks/E%20Book%20collection%20-%202026%20-%20B/RARE%20BOOKS/FACT%20Attribution%20Framework%20v1.0.pdf , the attribution from pamelang account to P
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:120
| **Protection** | Lock documents for tracked-changes-only, read-only, or comments-only with passwords |
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
sessions/2026-03-23-feature-expansion.md:12798
>      - Usage: `curl -sSL https://raw.githubusercontent.com/SecurityRonin/docx-mcp/main/install.sh | bash`
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
sessions/2026-03-23-feature-expansion.md:8131
>    The conversation evolved from DOCX report editing to planning a new open-source MCP server project. The most recent exchange was about discovery and distribution:
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
sessions/2026-03-23-feature-expansion.md:8137
>    The assistant researched MCP discovery channels: awesome-mcp-servers (PR + Glama), Smithery (smithery.ai/new), Glama (Add Server), mcpservers.org (submit form), ClawHub/ClawSkills (OpenClaw ecosy
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
sessions/2026-03-23-feature-expansion.md:9676
Yes — in the previous session, after building the initial `docx_mcp/document.py` and `server.py`, I smoke-tested against your real forensic report (`analysis/Digital Forensic Examination Report for DC
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 3ab2b904890bfull audit observations/trust-audit/mcp-server/securityronin__docx-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-083ab2b904890bSAFEB85first audit
06

Questions

What is the Docx MCP server?

MCP server for reading and editing Word (.docx) documents with track changes, comments, footnotes, and structural validation

What tools does Docx expose?

200 in total: 72 read-only, 119 that write, and 27 that can delete or overwrite (accept_changes, clear_run_formatting, delete_column_from_table, delete_comment, delete_content_control). Every one is listed on this page with its risk.

Is Docx safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (85/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 27 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Docx need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (3ab2b904890b), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement