# Word (nuget · WordMcp.McpServer)

Microsoft Word automation for AI assistants. Requires Word for Windows.

- Trust score: 73/100 (medium)
- Change this week: +3
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-20

## Components

- nuget · `WordMcp.McpServer`: 73/100 (this document), [markdown](https://verifymcp.io/servers/trsdn-mcp-server-word/wordmcp-mcpserver.md), [page](https://verifymcp.io/servers/trsdn-mcp-server-word/wordmcp-mcpserver)

## Channel facts

- Registry: `nuget`
- Package: `WordMcp.McpServer`
- Version: `0.1.0`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-20.

- **Supply Chain Security**: 88/100
  - No malware found by supply-chain analysis.
  - No known CVEs affecting this package version or its production dependencies.
  - Install-script risk not yet assessed.
  - No production dependencies, so there is no dependency health to assess.
- **Provenance & Transparency**: 35/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - License check failed: no license is declared.
  - Actively maintained (last published 26 days ago).
  - Publishes a security disclosure policy (SECURITY.md).
- **Schema Quality & AI Usability**: 64/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 3855 tokens (~257/item across 15 items; 15 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 90/100
  - Stability observed for 27 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 67/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 0% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 15 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 16 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the Word MCP server?

Word runs locally as a NuGet package, launched with dnx WordMcp.McpServer@0.1.0 --yes. Ready-made configuration for Claude, Cursor, VS Code, Codex and 3 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add trsdn-mcp-server-word -- dnx WordMcp.McpServer@0.1.0 --yes
```

### Cursor

```json
{
  "mcpServers": {
    "trsdn-mcp-server-word": {
      "command": "dnx",
      "args": [
        "WordMcp.McpServer@0.1.0",
        "--yes"
      ]
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "trsdn-mcp-server-word": {
      "command": "dnx",
      "args": [
        "WordMcp.McpServer@0.1.0",
        "--yes"
      ]
    }
  }
}
```

### Codex

```bash
codex mcp add trsdn-mcp-server-word -- dnx WordMcp.McpServer@0.1.0 --yes
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "trsdn-mcp-server-word": {
      "type": "local",
      "command": [
        "dnx",
        "WordMcp.McpServer@0.1.0",
        "--yes"
      ],
      "enabled": true
    }
  }
}
```

### Hermes

```yaml
mcp_servers:
  trsdn-mcp-server-word:
    command: "dnx"
    args: ["WordMcp.McpServer@0.1.0", "--yes"]
```

### Netclaw

```json
{
  "McpServers": {
    "trsdn-mcp-server-word": {
      "Transport": "stdio",
      "Command": "dnx",
      "Arguments": [
        "WordMcp.McpServer@0.1.0",
        "--yes"
      ]
    }
  }
}
```

### Other

```json
{
  "mcpServers": {
    "trsdn-mcp-server-word": {
      "command": "dnx",
      "args": [
        "WordMcp.McpServer@0.1.0",
        "--yes"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-20 (score 73, +1)

No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-18 (score 72, +1)

No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-15 (score 71, +1)

No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-13 (score 70, +1)

No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-11 (score 69, +1)

No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-09 (score 68, +1)

No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-07 (score 67, +1)

No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-05 (score 66, +1)

No change was recorded against any check on this day. Stability & Change Management went from 37 to 40. That category is still filling its 30-day observation window: 11 days of observed history at the previous scan, 12 at this one. The score rises as the window fills, whether or not the server changes.

## MCP tools (15)

### `paragraph` (~194 tokens)

Paragraph Operations

Paragraph operations on an open document. paragraph(list, session_id, skip=0, take=200) returns index, text, style, alignment and outline level. paragraph(add, session_id, text='...', style='Heading 1') appends a paragraph. paragraph(insert, session_id, index=3, text='...') inserts before paragraph 3. paragraph(delete|set-style|set-alignment, session_id, index=3, ...) edits an existing paragraph. Indexes are 1-based and shift after add, insert or delete — re-run list before further edits.

Input parameters:

- `action` (string, required)
- `alignment` (string|null)
- `include_empty` (boolean)
- `index` (integer|null)
- `session_id` (string, required)
- `skip` (integer)
- `style` (string|null)
- `take` (integer)
- `text` (string|null)

### `document` (~208 tokens)

Document Operations

Document-level operations. document(get-info, session_id) returns word/page/paragraph/table counts. document(get-properties|set-properties, session_id, title=..., author=...) reads or writes metadata. document(export-pdf, session_id, output_path='C:\\...\\report.pdf') writes a PDF without changing the document. document(save-as, session_id, output_path='C:\\...\\copy.rtf') saves a copy; the format follows the extension (.docx, .docm, .doc, .pdf, .rtf, .txt, .html) and the open document is saved as part of the operation.

Input parameters:

- `action` (string, required)
- `author` (string|null)
- `comments` (string|null)
- `company` (string|null)
- `keywords` (string|null)
- `output_path` (string|null)
- `session_id` (string, required)
- `subject` (string|null)
- `title` (string|null)

### `bookmark` (~254 tokens)

Bookmark Operations

Bookmark operations on an open document. bookmark(list, session_id) returns every bookmark with its name, paragraph index and a preview of the bookmarked text. bookmark(add, session_id, name="Intro", paragraph_index=2) bookmarks a paragraph; pass end_paragraph_index to span several paragraphs, or anchor_text to bookmark just a phrase inside the paragraph. bookmark(get-text, session_id, name="Intro") returns the full bookmarked text, which is the reliable way to re-read a passage after edits have shifted every index. bookmark(delete, session_id, name="Intro") removes the bookmark; the text stays. Bookmark names must start with a letter and may only contain letters, digits and underscores - Word rejects spaces and punctuation with an unhelpful error, so they are checked before the call reaches Word. Bookmarks survive edits elsewhere in the document, which makes them the stable way to refer to a passage across several calls.

Input parameters:

- `action` (string, required)
- `anchor_text` (string|null)
- `end_paragraph_index` (integer|null)
- `max_text_length` (integer)
- `name` (string|null)
- `paragraph_index` (integer|null)
- `session_id` (string, required)

### `style` (~364 tokens)

Style Operations

Style operations on an open document. Styles keep formatting consistent without touching every piece of text. style(list, session_id) returns only the styles the document actually uses; pass in_use_only=false for the complete list, which is over 370 entries on a localized Word. style(create, session_id, name='Callout', style_type='paragraph', base_style='Normal') adds a custom style. style(modify, session_id, name='Callout', font_name='Calibri', font_size=11, bold=true, color='#C00000', alignment='center', space_after=12) changes formatting; omitted properties stay as they are. style(delete, session_id, name='Callout') removes a custom style; built-in styles cannot be deleted. LOCALIZED NAMES: Word reports styles under localized names, so a German Word calls 'Heading 1' 'Ueberschrift 1'. Built-in styles are addressable by their English name; list returns both, and english_name is the one to send back. Sizes and spacing are in points (72 pt = 1 inch).

Input parameters:

- `action` (string, required)
- `alignment` (string|null)
- `base_style` (string|null)
- `bold` (boolean|null)
- `color` (string|null)
- `font_name` (string|null)
- `font_size` (number|null)
- `in_use_only` (boolean)
- `italic` (boolean|null)
- `line_spacing` (number|null)
- `name` (string|null)
- `session_id` (string, required)
- `space_after` (number|null)
- `space_before` (number|null)
- `style_type` (string|null)
- `underline` (boolean|null)

### `table` (~226 tokens)

Table Operations

Table operations on an open document. table(list, session_id) returns index, size and style of every table. table(create, session_id, rows=3, columns=4, style='Table Grid') appends a table. table(read, session_id, index=1) returns all cell values as rows. table(set-cell, session_id, index=1, row=1, column=2, text='Total') writes one cell. table(add-row, session_id, index=1, values=['a','b']) appends a filled row. table(delete-row|set-style, session_id, index=1, ...) edits an existing table. All indexes are 1-based.

Input parameters:

- `action` (string, required)
- `column` (integer|null)
- `columns` (integer|null)
- `index` (integer|null)
- `row` (integer|null)
- `rows` (integer|null)
- `session_id` (string, required)
- `style` (string|null)
- `text` (string)
- `values` (array|null)

### `field` (~241 tokens)

Field Operations

Field operations on an open document. field(insert-toc, session_id, lower_heading_level=3) inserts a table of contents at the top and fills it immediately. It stays EMPTY unless paragraphs use heading styles, so apply 'Heading 1'/'Heading 2' via paragraph(add, style=...) first; the result reports entry_count. field(insert-page-number, session_id, position='footer', alignment='center', include_total_pages=true) adds page numbers to every section. field(update-toc, session_id) refreshes the table of contents after content changed. field(update-all, session_id) refreshes every field including headers and footers. field(list, session_id) returns type, code and current result of each field.

Input parameters:

- `action` (string, required)
- `alignment` (string)
- `include_page_numbers` (boolean)
- `include_total_pages` (boolean)
- `lower_heading_level` (integer)
- `paragraph_index` (integer|null)
- `position` (string)
- `session_id` (string, required)
- `upper_heading_level` (integer)
- `use_hyperlinks` (boolean)

### `comment` (~216 tokens)

Comment Operations

Comment operations on an open document, the basis for review workflows. comment(list, session_id) returns every comment with its author, date, text and the document text it refers to. comment(add, session_id, paragraph_index=3, text='Please shorten this') attaches a comment to a whole paragraph; pass anchor_text to attach it to a phrase inside that paragraph instead. comment(resolve, session_id, index=1) marks a comment as done; pass resolved=false to reopen it. comment(delete, session_id, index=1) removes a comment. Comment indexes are 1-based and shift after every delete, so when removing several comments work from the highest index downwards. Paragraph indexes come from paragraph(list).

Input parameters:

- `action` (string, required)
- `anchor_text` (string|null)
- `index` (integer|null)
- `paragraph_index` (integer|null)
- `resolved` (boolean)
- `session_id` (string, required)
- `text` (string|null)
- `unresolved_only` (boolean)

### `image` (~281 tokens)

Image Operations

Inline image operations on an open document. image(list, session_id) returns index, size and alt text of every image. image(insert, session_id, image_path='C:/pics/chart.png', width=300, caption='Figure 1') appends an image; pass paragraph_index to place it before a specific paragraph. image(resize, session_id, index=1, scale_percent=50) or (index=1, width=200) resizes. image(replace, session_id, index=1, image_path=...) swaps the picture but keeps position and size. image(delete|set-alt-text, session_id, index=1, ...) edits an existing image. Sizes are in points (1 point = 1/72 inch), not pixels. All indexes are 1-based. Only inline images are covered, not floating shapes.

Input parameters:

- `action` (string, required)
- `alt_text` (string|null)
- `caption` (string|null)
- `height` (number|null)
- `image_path` (string|null)
- `index` (integer|null)
- `keep_size` (boolean)
- `lock_aspect_ratio` (boolean)
- `paragraph_index` (integer|null)
- `scale_percent` (number|null)
- `session_id` (string, required)
- `width` (number|null)

### `text` (~287 tokens)

Text Operations

Text operations on an open document. text(get, session_id) returns the full text; add start/end to read a character range. text(append, session_id, text='...') appends a paragraph at the end. text(find, session_id, text='term') returns match positions and context. text(replace, session_id, text='old', replace_text='new') replaces occurrences. text(format, session_id, start=0, end=20, bold=true, color='#0078D4') formats a character range. Positions are Word character offsets as reported by get and find.

Input parameters:

- `action` (string, required)
- `bold` (boolean|null)
- `color` (string|null)
- `end` (integer|null)
- `font_name` (string|null)
- `font_size` (number|null)
- `italic` (boolean|null)
- `match_case` (boolean)
- `match_whole_word` (boolean)
- `max_length` (integer)
- `max_results` (integer)
- `new_paragraph` (boolean)
- `replace_all` (boolean)
- `replace_text` (string|null)
- `search_text` (string|null)
- `session_id` (string, required)
- `start` (integer|null)
- `text` (string|null)
- `underline` (boolean|null)

### `screenshot` (~213 tokens)

Screenshot Operations

Renders a page of an open document as a PNG image. screenshot(page, session_id) renders page 1; pass page=3 for another page. Use this to check the layout visually - page breaks, table widths, image placement and header positions are far easier to judge from the rendered page than from measurements. The image is written to a file and the path is returned. Pass include_image=true to also get the PNG inline as base64, which is only worth it when the image is actually going to be looked at, since it is large. dpi defaults to 150, which is readable without being wasteful; 96 is enough for a rough layout check and 300 approaches print quality. Rendering goes through a PDF export of the single page, so unsaved changes are included.

Input parameters:

- `action` (string, required)
- `dpi` (integer)
- `include_image` (boolean)
- `output_path` (string|null)
- `page` (integer)
- `session_id` (string, required)

### `file` (~179 tokens)

File Operations

File and session management — the FIRST tool of every workflow. WORKFLOW: file(open, path='C:\\...\\report.docx') -> use session_id with document/text/paragraph/table tools -> file(close, save=true). NEW FILES: file(create, path='C:\\...\\new.docx') creates the file AND starts a session. REUSE: call file(list) first — if the document is already open, reuse its session_id. The file must be CLOSED in the Word desktop app; COM requires exclusive access. show=true makes Word visible. timeout_seconds: max time per operation (default 300).

Input parameters:

- `action` (string, required)
- `path` (string|null)
- `save` (boolean)
- `session_id` (string|null)
- `show` (boolean)
- `timeout_seconds` (integer)

### `section` (~246 tokens)

Section Operations

Section operations on an open document. A section owns the page setup and the headers and footers, so changing margins or orientation for part of a document means adding a section first. section(list, session_id) returns index, start type, margins, page size and orientation. section(add, session_id, start_type='next-page', paragraph_index=...) inserts a section break after that paragraph, or at the end when omitted. section(page-setup, session_id, section_index=2, orientation='landscape', top_margin=72) changes one section; without section_index it changes the whole document. ALL MEASUREMENTS ARE IN POINTS: 72 pt = 1 inch = 2.54 cm.

Input parameters:

- `action` (string, required)
- `bottom_margin` (number|null)
- `left_margin` (number|null)
- `orientation` (string|null)
- `paper_size` (string|null)
- `paragraph_index` (integer|null)
- `right_margin` (number|null)
- `section_index` (integer|null)
- `session_id` (string, required)
- `start_type` (string)
- `top_margin` (number|null)

### `revision` (~217 tokens)

Revision Operations

Tracked change operations on an open document. revision(list, session_id) returns every tracked change with its type, author, date and affected text, plus whether tracking is currently on. revision(accept, session_id) accepts every change; pass index=1 to accept a single one. revision(reject, session_id, index=2) discards a change the same way. revision(set-tracking, session_id, enabled=true) turns change tracking on or off, which is what makes later edits show up as revisions in the first place. Revision indexes are 1-based and shift after every accept or reject, so when handling several changes individually work from the highest index downwards, or just accept or reject them all at once. Accepting or rejecting everything also covers headers and footers, which Word's own AcceptAllRevisions does not.

Input parameters:

- `action` (string, required)
- `author` (string|null)
- `enabled` (boolean|null)
- `index` (integer|null)
- `session_id` (string, required)

### `header-footer` (~204 tokens)

Header and Footer Operations

Header and footer operations on an open document. Headers belong to a SECTION, not to the document, so use section(list) first when a document has more than one. header-footer(set, session_id, kind='footer', text='Confidential') writes the same text to every section; pass section_index to target one. type='first-page' or 'even-pages' switches the matching section option on automatically, because Word otherwise stores the text without ever showing it. Writing to a section whose header is inherited from the previous one breaks that link. header-footer(get, session_id, kind='header') reads the text back. For page numbers use field(insert-page-number) instead, which inserts live fields.

Input parameters:

- `action` (string, required)
- `alignment` (string|null)
- `kind` (string)
- `section_index` (integer|null)
- `session_id` (string, required)
- `text` (string|null)
- `type` (string)

### `list` (~289 tokens)

List Operations

Bullet and numbered list operations on an open document. list(apply, session_id, start_index=2, end_index=5, list_type='number') turns a range of paragraphs into a numbered list; list_type can be bullet, number or outline-number. list(set-level, session_id, start_index=3, end_index=4, level=2) indents paragraphs to a sub-level; levels run from 1 to 9 and only outline-number lists render a distinct format per level. list(restart, session_id, start_index=6) starts the numbering over at that paragraph, which is how two separate numbered lists are kept apart. list(remove, session_id, start_index=2, end_index=5) strips the list formatting again. list(get, session_id) reports the list formatting of every paragraph, including the bullet or number Word renders. Paragraph indexes are 1-based and shift whenever paragraphs are added or removed, so read them with paragraph(list) right before using them. Omitting end_index applies the action to start_index alone.

Input parameters:

- `action` (string, required)
- `continue_previous_list` (boolean)
- `end_index` (integer|null)
- `level` (integer|null)
- `list_type` (string)
- `listed_only` (boolean)
- `session_id` (string, required)
- `start_index` (integer|null)

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/trsdn-mcp-server-word/wordmcp-mcpserver#diagnostics

## Score history

- 2026-09-20: 73
- 2026-09-19: 72
- 2026-09-18: 72
- 2026-09-17: 71
- 2026-09-16: 71
- 2026-09-15: 71
- 2026-09-14: 70
- 2026-09-13: 70
- 2026-09-12: 69
- 2026-09-11: 69
- 2026-09-10: 68
- 2026-09-09: 68
- 2026-09-08: 67
- 2026-09-07: 67
- 2026-09-06: 66
- 2026-09-05: 66
- 2026-09-04: 65
- 2026-09-03: 65
- 2026-09-02: 64
- 2026-09-01: 64
- 2026-08-31: 60
- 2026-08-30: 60
- 2026-08-29: 60
- 2026-08-28: 60
- 2026-08-27: 60
- 2026-08-26: 60
- 2026-08-25: 58
- 2026-08-24: 58

## Common questions

### What is the Word MCP server?

Word is an MCP server listed in the public MCP registry as io.github.trsdn/mcp-server-word. Microsoft Word automation for AI assistants. Requires Word for Windows. This page covers its NuGet package (WordMcp.McpServer).

### Is the Word MCP server safe to use?

Word scores 73 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Word MCP server expose?

Word exposes 15 tools: paragraph, document, bookmark, style, table, and 10 more. Their descriptions and schemas cost roughly 3,619 tokens of context every time the server is loaded.

### Is the Word MCP server still maintained?

Word is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- NuGet package: https://www.nuget.org/packages/WordMcp.McpServer
- Socket report: https://socket.dev/nuget/package/WordMcp.McpServer
- Repository: https://github.com/trsdn/mcp-server-word
- Changelog RSS feed: https://verifymcp.io/servers/trsdn-mcp-server-word/wordmcp-mcpserver.xml
- Changelog JSON feed: https://verifymcp.io/servers/trsdn-mcp-server-word/wordmcp-mcpserver.json
- HTML version of this page: https://verifymcp.io/servers/trsdn-mcp-server-word/wordmcp-mcpserver
