Kordoc handles Korean formats that general converters skip
Kordoc's reason to exist is HWP. It reads HWP 3.x, HWP 5.x, HWPX, and HWPML, then turns them into Markdown plus structured blocks. It can also compare old and new versions, fill preserved forms, patch text into an original document, place a seal, redact personal data, and generate HWPX from Markdown. PDF, DOCX, XLS, XLSX, and common image formats broaden the input side.
The package exposes those jobs through a TypeScript API, CLI, and 17 MCP document tools. Its setup command can configure Claude Desktop, Claude Code, Cursor, VS Code, Codex, and other clients. This matters because an agent can work on an actual HWPX form instead of receiving pasted plain text with tables already damaged. The maintainer still tells users to review redaction before publication, a sensible boundary for official records.
The clean test run comes with a 1,384 MB install
Our fresh Debian sandbox installed 254 packages in 53 seconds at commit bb71f7f. The checked-out repository contained 639 files, about 112,822 lines of source, and occupied 13 MB before dependencies. After npm finished, the environment used 1,384 MB. There are two CI workflow files and a tests directory, but no Dockerfile. The package is easy to invoke and expensive to carry.
PDF and OCR support account for part of that weight and install by default. --omit=optional makes the footprint smaller at the cost of both features. The built-in Korean OCR can download a model of about 18 MB on first use, while formula OCR needs another model around 155 MB. Printing Markdown to PDF also requires a separate puppeteer-core install. Plan the image around the format paths you will actually enable.
What happened when we ran it
Our run built Kordoc in 17 seconds after the 53-second install. Node's test runner then completed in 126 seconds with 2,608 passed and 0 failed. Npm audit reported 0 known vulnerabilities across critical, high, moderate, and low severities. The container had 3 CPUs, 8 GB of RAM, Node 22, no secrets, and no elevated privileges.
Those results cover the repository's supplied suite, not our own corpus of government files. We did not verify the README's published PDF benchmark, OCR accuracy, or HWPX table fidelity claims. A document parser earns trust file by file because one dropped unit symbol can change meaning while the command still exits successfully. The 2,608 passing tests are a strong start, followed by fixtures from your archive and output comparisons on tables, formulas, and page boundaries.
DOCX equations and symbols still need spot checks
Five open issues on September 29 describe narrow but consequential DOCX failures. Issue 104 says inline equations move to the end of a paragraph. Issue 105 reports Symbol-font characters such as degree, multiplication, and micro signs disappearing. Issue 107 covers text lost inside bidirectional elements, and issue 106 shows malformed LaTeX around angle brackets and equation numbers. These are poor fits for unattended scientific ingestion.
Issue 108 documents a separate 100 MB uncompressed-size ceiling for DOCX packages. The parser rejects the file before reading even when images: false, so a document with heavily compressed media can hit the limit despite a small upload size. The safety reason is ZIP-bomb protection. The operational answer is to test actual large files rather than raise a reverse proxy's upload limit and assume parsing will follow.
Offline mode is useful only after models and roots are prepared
Kordoc can run without a cloud document API. KORDOC_OFFLINE=1 blocks external communication, and its model commands can export assets on a connected machine for import into an isolated network. KORDOC_ROOT restricts MCP file access to a chosen directory. Those controls suit sensitive records, provided the deployment includes every OCR model and font dependency needed before the network disappears.
Version 4.16.3 also fixed a concrete file-boundary flaw. The release notes say MCP document generation could follow a symlink inside an image directory and include a file outside KORDOC_ROOT. The shared loader now checks real paths, refuses symlink traversal for individual files, and requires ordinary files. That same-day security release is evidence of responsive maintenance, while also showing why an MCP parser deserves filesystem containment.
Same-day maintenance is active, and the format surface is young
GitHub showed 2,284 stars and 5 open issues and pull requests on September 29, 2026. Version 4.16.3 and the latest repository push both landed that day. The project began in March 2026, so a v4 label should not be read as years of stable production history. Its current issue queue is small, detailed, and tied to reproducible documents.
Kordoc is the first tool we would trial when HWP or HWPX is nonnegotiable. Our 2,608-test run and clean npm audit make that trial easier to defend. Adoption still needs a representative corpus, especially for DOCX science files, documents above 100 MB uncompressed, and generated pages containing equations. If those checks pass, the package replaces several format-specific scripts with one local interface.

