Atlas / MCP servers / ykarapazar / Word Live

Word LiveSAFE

mcp/ykarapazar/word-live

The only MCP server that edits Word documents while they're open — 114 tools, live editing, tracked changes, per-action undo

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
—
Transport
sse · stdio · streamable-http
License
MIT
Stars
228
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://cursor.com/en/install-mcp?name=word&config=eyJjb21tYW5kIjoidXZ4IiwiYXJncyI6WyJ3b3JkLW1jcC1saXZlIl19)

The only MCP server that edits Word documents while they're open

Live editing · Tracked changes · Per-action undo · 124 tools · Cross-platform

[](https://pypi.org/project/word-mcp-live/) [](https://www.python.org/downloads/) [](LICENSE) []()

word-mcp-live gives any AI assistant that supports MCP full control of Microsoft Word. Open a document, tell the AI what you need, and watch it happen — formatting, tracked changes, comments, and all. Changes appear live in your open document.

Without word-mcp-live

  • AI can discuss your document but can't touch it
  • You copy-paste between AI and Word, losing formatting
  • Track changes? You do those manually after the fact
  • Every edit means save → close → process → reopen

With word-mcp-live

  • "Add a tracked change replacing ABC Corp with XYZ Ltd" — done
  • Changes appear live in your open Word document
  • Every AI edit is one Ctrl+Z away
  • Real tracked changes with your name, not XML hacks

See it in action

https://github.com/user-attachments/assets/fbb09af4-1e25-4e49-94d0-45b363278810

What Sets This Apart

  • Live editing — Edit documents while they're open in Word. No save-close-reopen cycle.
  • Full undo — Every AI action is a single Ctrl+Z. Made a mistake? Just undo it.
  • Native tracked changes — Real Word revisi
Read from source at commit 347e58d4421cOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add word-mcp-live -- None word-mcp-live==1.3.0
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
fastmcp, python-docx, msoffcrypto-tool, docx2pdf, python-dotenv
Why it matters. 5 requirement(s) not pinned with ==
Fix. pin exact versions
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 347e58d4421cfull audit observations/trust-audit/mcp-server/ykarapazar__word-live.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06347e58d4421cSAFEB89first audit
05

Questions

What is the Word Live MCP server?

The only MCP server that edits Word documents while they're open — 114 tools, live editing, tracked changes, per-action undo

Is Word Live safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Word Live need?

It reads MCP_AUTHOR and MCP_AUTHOR_INITIALS from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Word Live run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as word-mcp-live.

How current is this page?

The grade is for one exact copy of the source (347e58d4421c), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement