Docx Editing
Surgically edit existing (brownfield) .docx files with formatting preservation and tracked changes via the Safe-DOCX MCP server. Use when user says "edit thi...
Rank
62
Safety
84
Downloads
1.9k
Updated
Oct 9, 2026
Version
0.3.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.9K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 1.9K downloadsadoption · observed Oct 9, 2026
- Latest release
- 0.3.0release · observed Apr 8, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17846kvqgde4k0takks4byt0184fe4h:docx-editing- Install using `clawhub skill install s17846kvqgde4k0takks4byt0184fe4h:docx-editing` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/stevenobiajulu/docx-editing before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-stevenobiajulu-docx-editing/snapshot"
Documentation
CLAWHUB
57,232 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
---
name: docx-editing
description: >-
Surgically edit existing (brownfield) .docx files with formatting preservation
and tracked changes via the Safe-DOCX MCP server. Use when user says "edit this
docx," "change the contract," "redline the document," "compare these Word files,"
"add a comment to the docx," "read this Word file," or "mark up the agreement."
Not for from-scratch document generation.
license: MIT
compatibility: >-
Works with any MCP-compatible agent. Requires Node.js >=18.0.0 and npm
(for npx) on the host machine. The MCP server runs locally as a stdio
child process. Install-time: npm registry fetch (one-time, cacheable).
Runtime: zero network calls, file access limited to ~/ and system temp.
requires:
binaries:
- node (>=18.0.0)
- npx (bundled with npm)
network:
install_time: npm registry (registry.npmjs.org) — one-time fetch
runtime: none
filesystem:
- ~/ (home directory)
- system temp directories
metadata:
author: safe-docx
version: "0.3.0"
---
# Editing .docx Files with Safe-DOCX
Safe-DOCX is a local MCP server for surgically editing existing `.docx` files. It preserves formatting, generates tracked-changes redlines, and — once installed — runs entirely on the local filesystem with zero network activity.
## Source Code and Audit
Safe-DOCX is fully open source (MIT license). Review the complete source before installing:
- **GitHub**: https://github.com/UseJunior/safe-docx
- **npm registry**: https://www.npmjs.com/package/@usejunior/safe-docx
- **Code coverage**: Published via Codecov on every release
- **Conformance harness**: Automated spec coverage tests run in CI on every commit
- **No postinstall scripts** — verify: `npm view @usejunior/safe-docx scripts` shows no `postinstall` or `install` hooks
All security claims below are verifiable by reading the source.
## Runtime Requirements
Safe-DOCX requires these binaries to be available on the host:
| Binary | Minimum version | Why |
|--------|-----------------|-----|
| `node` | 18.0.0 | Authoritative version from `packages/safe-docx/package.json` engines field |
| `npx` | Bundled with npm | Used by the recommended MCP connector to launch the server |
If you prefer not to use `npx`, see **Offline / Pinned Installation** below for alternatives.
## Safety Model
Safe-DOCX's safety model has two distinct phases: **install time** (when the package is fetched) and **runtime** (when the MCP server is running).
### Install-Time Behavior (network required, one-time)
- **npm registry fetch** — the recommended connector command `npx -y @usejunior/safe-docx` downloads the package from `registry.npmjs.org` on first run. Subsequent runs use the cached copy unless the cache is cleared.
- **No postinstall scripts** — the package declares no `postinstall`, `preinstall`, or `install` hooks. Verify with `npm view @usejunior/safe-docx scripts`.
- **Provenance** — releases are published with npm provenance (`--provenance`), so you can _meta.json
{
"ownerId": "kn7cxqj3xb7acyyg6jkynq46bd814sv2",
"slug": "docx-editing",
"version": "0.3.0",
"publishedAt": 1775654758792
}CONNECTORS.md
# Safe-DOCX MCP Connectors How to connect the Safe-DOCX MCP server to your AI editor or desktop client. ## Requirements | Binary | Minimum version | Notes | |--------|-----------------|-------| | `node` | 18.0.0 | Authoritative from `package.json` engines field | | `npm` / `npx` | Bundled with Node.js | Only needed for the `npx` connector path | ## Summary | Property | Value | |----------|-------| | Transport | stdio | | Command (default) | `npx` | | Args | `["-y", "@usejunior/[email protected]"]` (pinned) | | API keys | None required | | Path policy | `~/` and system temp dirs (default) | | Install-time network | npm registry, one-time fetch | | Runtime network | None | ## Claude Desktop (pinned version, recommended) Add to `claude_desktop_config.json`: ```json { "mcpServers": { "safe-docx": { "command": "npx", "args": ["-y", "@usejunior/[email protected]"] } } } ``` Pinning the version prevents unexpected updates. Check the [CHANGELOG](https://github.com/UseJunior/safe-docx/blob/main/CHANGELOG.md) before bumping. ## Cursor Add to `.cursor/mcp.json` in your project root: ```json { "mcpServers": { "safe-docx": { "command": "npx", "args": ["-y", "@usejunior/[email protected]"] } } } ``` ## Offline / High-Security Install For environments where `npx` fetching from npm is unacceptable, install the package manually and invoke the installed binary directly: ```bash # Install a specific pinned version globally npm install -g @usejunior/[email protected] ``` Then configure your MCP client to use the installed binary: ```json { "mcpServers": { "safe-docx": { "command": "safe-docx", "args": [] } } } ``` This eliminates the runtime `npx` fetch entirely. The MCP server has zero outbound network calls once installed. ### Vendored install To vendor the package into your project without touching a registry at run time: ```bash npm pack @usejunior/[email protected] # Inspect the tarball, then: npm install -g ./usejunior-safe-docx-0.9.0.tgz ``` ### Build from source For maximum auditability: ```bash git clone https://github.com/UseJunior/safe-docx.git cd safe-docx git checkout v0.9.0 npm ci npm run build npm link packages/safe-docx ``` ## Notes - **No API keys** — Safe-DOCX runs locally and does not call external services. - **Path policy** — By default, only files under the home directory (`~/`) and system temp directories are accessible. Symlinks must resolve to allowed roots. - **Install-time vs runtime network** — The default `npx` connector fetches the package from npm on first run. After install, the server has zero outbound network calls. Use the offline install path above if one-time install fetching is unacceptable. - **No postinstall scripts** — The package declares no `postinstall`, `preinstall`, or `install` hooks. Verify with `npm view @usejunior/safe-docx scripts`. - **Provenance** — Releases are published with npm provenance, so each published version can be cr
skill-card.md
## Description: Docx Editing helps agents surgically edit existing .docx files with formatting preservation and tracked changes through the local Safe-DOCX MCP server. This skill is ready for commercial/non-commercial use. ## Publisher: [stevenobiajulu](https://clawhub.ai/user/stevenobiajulu) ### License/Terms of Use: MIT-0 ## Use Case: Developers, editors, legal reviewers, and other document-focused users use this skill to read, revise, comment on, compare, and save existing Word documents while preserving formatting and producing tracked-change redlines. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The MCP server can access DOCX files under the user's home directory and system temp folders. Mitigation: Use the skill only with explicit document paths, keep edits directed at intended input files, and avoid running it in workspaces containing unrelated sensitive documents. Risk: The default npx connector performs a one-time npm registry fetch during setup, which may be unsuitable for restricted environments. Mitigation: Use the pinned or vendored installation path, review the package or source before use, and invoke the installed safe-docx binary directly where registry access is not allowed. Risk: Automated document edits or redlines can introduce incorrect language into contracts, agreements, or other high-impact documents. Mitigation: Review clean and tracked-change outputs before relying on them, especially for legal, financial, or customer-facing documents. ## Reference(s): - [Safe-DOCX GitHub repository](https://github.com/UseJunior/safe-docx) - [Safe-DOCX npm package](https://www.npmjs.com/package/@usejunior/safe-docx) - [Safe-DOCX stdio server source](https://github.com/UseJunior/safe-docx/blob/main/packages/safe-docx/src/server.ts) - [Safe-DOCX changelog](https://github.com/UseJunior/safe-docx/blob/main/CHANGELOG.md) - [Connector setup guide](CONNECTORS.md) ## Skill Output: **Output Type(s):** [text, markdown, code, shell commands, configuration, guidance] **Output Format:** [Markdown guidance with inline commands, JSON connector snippets, and agent tool-use instructions] **Output Parameters:** [1D] **Other Properties Related to Output:** [May direct the agent to save clean and tracked-change DOCX files, produce structured revision JSON, or provide setup commands for MCP connectors.] ## Skill Version(s): 0.3.0 (source: server evidence and frontmatter) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/stevenobiajulu/skills/docx-editing",
"sourceUrl": "https://clawhub.ai/stevenobiajulu/skills/docx-editing",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T22:56:37.331Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-stevenobiajulu-docx-editing/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-stevenobiajulu-docx-editing/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T22:56:37.331Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.9K downloads",
"href": "https://clawhub.ai/stevenobiajulu/docx-editing",
"sourceUrl": "https://clawhub.ai/stevenobiajulu/docx-editing",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T22:56:37.331Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.3.0",
"href": "https://clawhub.ai/stevenobiajulu/docx-editing",
"sourceUrl": "https://clawhub.ai/stevenobiajulu/docx-editing",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-04-08T13:25:58.792Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-stevenobiajulu-docx-editing/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-stevenobiajulu-docx-editing/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.3.0",
"description": "Address ClawHub security scan feedback: declare required binaries (node >=18, npx) in frontmatter; separate install-time vs runtime safety model; add offline/pinned install path; fix Node version inconsistency (was >=20, now matches package.json >=18); add no-postinstall-scripts disclosure and npm provenance note",
"href": "https://clawhub.ai/stevenobiajulu/docx-editing",
"sourceUrl": "https://clawhub.ai/stevenobiajulu/docx-editing",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-04-08T13:25:58.792Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
