Atlas / MCP servers / zxyasfas / Paper Format Agent

Paper Format AgentBLOCK

mcp/zxyasfas/paper-format-agent

DOCX formatter for academic papers with a content-fingerprint guard: proves your text is never altered, only the formatting. Also installable as an agent skill. 毕业论文、学位论文的 Word 自动排版:按格式要求改字体字号、行距、缩进、标题和题注;指纹校验保证只改格式、不动正文,也可做格式检查评分。

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
3 3r · 0w · 0d
Transport
stdio
License
MIT
Stars
81
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

中文说明 | English

A local DOCX formatter for theses and papers.

It changes fonts, spacing, indents, headings and captions to match a format guide. It does not rewrite the paper. Before saving, it compares a fingerprint of the body and table text from before and after the run. If the text changed, it aborts instead of writing the formatted file.

Everything runs on your machine. Nothing is uploaded.

the content check

Report fields from a real run (--engine python):

{
"content_fingerprint_before": "793e6533fd670418141d11fdcf014be19750408129ecff8b1b78a2641a3786db",
"content_fingerprint_after":  "793e6533fd670418141d11fdcf014be19750408129ecff8b1b78a2641a3786db",
"content_changed": false,
"content_guard_enforced": true
}

The two hashes should match. If they don't, the formatter exits with content guard failed and the formatted DOCX is not written.

What the check covers: body paragraphs and tables, with whitespace and stray bullet characters normalized before comparing. Headers and footers are out of scope because the formatter sets those on purpose. Use --engine python when the fingerprint must cover the final saved DOCX; the other engines run a local post-processor after the check, e.g. to refresh the table of contents.

To watch the guard trip, run python tools/demo_content_guard.py. It formats a synthetic paper, then repeats the run with the styling step patched to edit one sentence of the in-memory document. The second run aborts without writing the DOCX.

docs/BENCHMARK.md tracks which authored strings survive a run in small synthetic fixtures, and lists the known gaps.

install and run

pip i
Read from source at commit fd17ff47b0d9OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add paper-format-agent -- None paper-format-agent==3.1.0
03

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
extract_format_rulesreadExtract structured formatting rules from a format guide, without changing any file.
format_paperreadReformat an academic paper DOCX to match a format guide, content-guarded.
score_paperreadScore a paper against a format guide read-only, without modifying it.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (7)

HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
.github/ISSUE_TEMPLATE/bug_report.md:1
---
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
.github/ISSUE_TEMPLATE/feature_request.md:1
---
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
CODE_OF_CONDUCT.md:1
# Contributor Covenant Code of Conduct
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
SECURITY.md:1
# Security Policy
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/ARCHITECTURE.md:1
# Architecture (V3)
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
paper_format_agent/batch.py:51
digest = hashlib.sha1(str(relative).replace("\\", "/").encode("utf-8")).hexdigest()[:8]
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
python-docx, lxml, langgraph
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha fd17ff47b0d9full audit observations/trust-audit/mcp-server/zxyasfas__paper-format-agent.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07fd17ff47b0d9BLOCKD69first audit
06

Questions

What is the Paper Format Agent MCP server?

DOCX formatter for academic papers with a content-fingerprint guard: proves your text is never altered, only the formatting. Also installable as an agent skill. 毕业论文、学位论文的 Word 自动排版:按格式要求改字体字号、行距、缩进、标题和题注;指纹校验保证只改格式、不动正文,也可做格式检查评分。

What tools does Paper Format Agent expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Paper Format Agent safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Paper Format Agent need?

It reads DEEPSEEK_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Paper Format Agent run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as paper-format-agent.

How current is this page?

The grade is for one exact copy of the source (fd17ff47b0d9), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement