Word LiveSAFE
The only MCP server that edits Word documents while they're open — 114 tools, live editing, tracked changes, per-action undo
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://cursor.com/en/install-mcp?name=word&config=eyJjb21tYW5kIjoidXZ4IiwiYXJncyI6WyJ3b3JkLW1jcC1saXZlIl19)
The only MCP server that edits Word documents while they're open
Live editing · Tracked changes · Per-action undo · 124 tools · Cross-platform
[](https://pypi.org/project/word-mcp-live/) [](https://www.python.org/downloads/) [](LICENSE) []()
word-mcp-live gives any AI assistant that supports MCP full control of Microsoft Word. Open a document, tell the AI what you need, and watch it happen — formatting, tracked changes, comments, and all. Changes appear live in your open document.
Without word-mcp-live
- AI can discuss your document but can't touch it
- You copy-paste between AI and Word, losing formatting
- Track changes? You do those manually after the fact
- Every edit means save → close → process → reopen
With word-mcp-live
- "Add a tracked change replacing ABC Corp with XYZ Ltd" — done
- Changes appear live in your open Word document
- Every AI edit is one Ctrl+Z away
- Real tracked changes with your name, not XML hacks
See it in action
https://github.com/user-attachments/assets/fbb09af4-1e25-4e49-94d0-45b363278810
What Sets This Apart
- Live editing — Edit documents while they're open in Word. No save-close-reopen cycle.
- Full undo — Every AI action is a single Ctrl+Z. Made a mistake? Just undo it.
- Native tracked changes — Real Word revisi
347e58d4421cOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add word-mcp-live -- None word-mcp-live==1.3.0
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
.mcpbignore
fastmcp, python-docx, msoffcrypto-tool, docx2pdf, python-dotenv
Gates applied: no_behavioural_pass.
347e58d4421cfull audit observations/trust-audit/mcp-server/ykarapazar__word-live.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 347e58d4421c | SAFE | B | 89 | first audit |
Questions
What is the Word Live MCP server?
The only MCP server that edits Word documents while they're open — 114 tools, live editing, tracked changes, per-action undo
Is Word Live safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Word Live need?
It reads MCP_AUTHOR and MCP_AUTHOR_INITIALS from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Word Live run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as word-mcp-live.
How current is this page?
The grade is for one exact copy of the source (347e58d4421c), read on 2026-10-06. The repository is watched and re-audited when it changes.