HermesOffice
A free, open-source AI office suite that edits real Office files locally — Word, Excel, PowerPoint, PDF and Markdown.
- Source repo
- criptogus/HermesOffice
- Stars
- ★ 606
- Last updated
- 11d ago
- License
- Apache-2.0
- Primary language
- TypeScript
- FA score
- 57/100 · Major gaps
At a glance
- How it runs
- Works with
- Portable with changesOpenAI API · Claude API
- Cost
- Free software; you pay for model usage
- Setup effort
- Medium · a few setup steps
- You'll need
- Typical use
- Legal or document-control teams that round-trip .docx files through a non-Microsoft tool and cannot afford layout drift — only dirty paragraphs are rewritten and the rest survives byte-for-byte.
- Not a fit if
- Users who want a browser-only tool and won't install a desktop client
- Enterprises that require notarized, fully signed builds
- Source review
- 57/100 · Major gaps
What does this agent do, and when should you use it?
HermesOffice is an open-source office suite for macOS, Windows and Linux, shipped as six Electron apps — Docs, Sheets, Slides, PDF, Markdown and a suite shell — that all sit on one shared engine layer. It opens and saves genuine Microsoft Office formats (.docx, .xlsx, .pptx) and also edits PDF and Markdown. Its defining design choice is that the original file stays the source of truth: the file is archived by hash on open, only dirty blocks are regenerated into OOXML fragments and spliced back into document.xml, and everything untouched is copied byte-for-byte, so files do not reflow when reopened in Word. AI is treated as a first-class editing workflow rather than a chat sidebar: Docs does block-level edits with snapshots and diffs, while the other apps expose tool-calling agents over workbook, slide and PDF state. Model backends run either through a keyless Genspark device-code sign-in or BYOK for Claude, OpenAI, Gemini, DeepSeek and any OpenAI-compatible endpoint.
Each app has a defined job. apps/docs reads and writes .docx with byte-level paragraph patching, a paginated view, tracked changes, comments, styles and equations. apps/sheets is built on the open-source Univer core plus substantial in-house extensions, with .xlsx import/export handled by an in-house Rust sidecar (calamine + IronCalc), Konva-rendered charts, pivot tables, slicers and conditional formatting. apps/slides uses an in-house .pptx parse/render/edit engine covering masters, layouts, charts, crop and ink. apps/pdf layers pdf.js and pdf-lib over PDFium wasm, rewriting page content streams so text edits and image inserts are real edits with original fonts subset-embedded, plus annotations, forms, outlines, stamps, signatures, page operations and printing. apps/markdown is a Tiptap block editor over plain Markdown files. packages/pdf2docx converts PDF to DOCX entirely on-device using PDFium character-level extraction and geometry-only layout analysis, and the same analysis drives the PDF app's PowerPoint and Excel exports, including system-OCR handling of scanned pages on macOS and Windows. packages/agent-core, ai-provider and ai-search supply the shared agent loop, streaming provider abstraction and web/image search tools.
- Legal or document-control teams that round-trip .docx files through a non-Microsoft tool and cannot afford layout drift — only dirty paragraphs are rewritten and the rest survives byte-for-byte.
- Anyone holding a scanned or native PDF contract or paper who wants it converted into an editable .docx, .pptx or .xlsx locally, without uploading to a cloud service.
- Publishing and bid teams that need real PDF text and image editing with original fonts preserved rather than white-box cover-up annotations.
- Teams already paying for Claude, OpenAI or a local model server who want those models wired into document editing on their own API keys.
- macOS Apple Silicon users looking for a free Microsoft Office alternative: one .dmg, one click, macOS 11+.
- Developers embedding document editing in Electron and wanting to reuse the engine layer — docx-engine, pptx-engine and pdf2docx are Electron-free TypeScript packages.
How do you install or deploy this agent?
The shortest path is macOS on Apple Silicon, where the release link always points at the newest build:
# macOS Apple Silicon (.dmg)
https://github.com/criptogus/HermesOffice/releases/latest/download/HermesOffice-arm64.dmg
# macOS Apple Silicon (.zip)
https://github.com/criptogus/HermesOffice/releases/latest/download/HermesOffice-arm64-mac.zipThe macOS bundle is ad-hoc signed and not notarized, so the first launch needs one confirmation: right-click the app → Open, or allow it under System Settings → Privacy & Security.
macOS Intel, Windows and every Linux distribution currently have no published artifact and must be built from source. Install dependencies and generate test fixtures first:
npm install
npm run fixtures # generate test .docx fixtures
npm test # engine + app unit tests
npm run typecheck # tsc --noEmit across every workspacePackage per platform (Sheets needs cargo on PATH; its Rust sidecar is compiled automatically):
npm run dist:mac # package macOS dmg (regenerates third-party notices)
npm run dist:win # package Windows nsis installer
npm run dist:linux # package Linux AppImage + deb + rpmIf you already have Linux artifacts, install per distribution:
sudo apt install ./hermesoffice_<version>_amd64.deb
sudo dnf install ./hermesoffice-<version>.x86_64.rpm # Fedora / RHEL family
sudo zypper install ./hermesoffice-<version>.x86_64.rpm # openSUSE
# The AppImage needs the FUSE 2 runtime
sudo apt install libfuse2
chmod +x HermesOffice-<version>.AppImage
./HermesOffice-<version>.AppImageAI features need credentials: by default you complete a Genspark device-code sign-in with no model API key, or you enter your own key in AI settings (Claude, OpenAI, Gemini, DeepSeek, Kimi, GLM, Qwen, Doubao, MiniMax, Grok, Mistral, OpenRouter, or any OpenAI-compatible endpoint via base URL + key).
How do you use this agent?
Launch the suite shell, use the home screen to open Docs, Sheets, Slides, PDF or Markdown in tabs, and work on documents — opening, editing and saving all happen locally.
During development you can run every editor at once or a single workspace:
npm run dev # all five editors + shell against Vite dev servers
npm run dev:docs # a single appLocal UI/e2e driver scripts (Playwright + Electron, not committed by default) live in scripts/drivers/.
Typical AI flow: open the AI panel in any app → if not signed in, either complete the Genspark device-code flow or pick a BYOK provider in AI settings and paste your key → in Docs, ask for a block-level rewrite and review the generated snapshot and diff before keeping it; in Sheets, Slides and PDF the agent reads and writes the current workbook, presentation or page state through tool calls.
What are this agent's strengths and limitations?
- Byte-preserving .docx round trip: only dirty paragraphs are regenerated (paragraph patch) and the untouched parts are written back byte-for-byte, so Word layout survives; Sheets and Slides follow the same original-file-is-truth policy.
- PDF editing is real editing, not cover-up: page content streams are rewritten through PDFium wasm with original fonts subset-embedded, covering both text and image inserts.
- PDF → Word/PowerPoint/Excel conversion runs fully on-device, with system OCR on macOS and Windows for scanned pages, so documents never need to be uploaded.
- No model lock-in: keyless Genspark device-code sign-in, BYOK for a dozen-plus providers, and a custom slot for any OpenAI-compatible endpoint including local model servers.
- Clean engine/app split: docx-engine, pptx-engine, pptx-render, pdf2docx, agent-core and ai-provider are Electron-free TypeScript packages with unit tests.
- Permissive licensing: Apache-2.0, with only the ee/ directory reserved for future enterprise modules under a separate license.
- The only published artifact is macOS Apple Silicon (arm64); Windows, Linux and macOS Intel are all build-from-source only.
- The macOS bundle is ad-hoc signed and not notarized, so first launch requires a manual bypass — extra friction for managed enterprise rollout.
- AI features need a network connection; whether you use Genspark sign-in or BYOK, only non-AI editing works fully offline.
- Building from source is heavy: a Node.js toolchain, plus Rust/cargo for the Sheets sidecar and FUSE 2 for the Linux AppImage.
- Official packaged builds send limited usage analytics by default (disable under Settings → General), which privacy-sensitive environments must configure away.
- The HermesOffice and Genspark names and logos are Mainfunc, Inc. trademarks that Apache-2.0 does not grant, so forks must rebrand.
How does this agent compare with similar options?
The README positions HermesOffice explicitly as a free, open-source alternative to Microsoft Office and frames its compatibility around Microsoft Word, Excel and PowerPoint file formats. It also credits a set of upstream open-source projects it builds on (Electron, Univer, PDFium, pdf.js, pdf-lib, Tiptap/ProseMirror, Konva, HarfBuzz, calamine, IronCalc) — those are dependencies, not competing products. The source names no other office suite or AI document agent, so no competitor comparison is made here.
Key facts side by side with the most closely related agents.
| Agent | Source review | Form / cost | Stars | Updated | Language | Full support on |
|---|---|---|---|---|---|---|
| HermesOffice This agent | 57 · Major gaps | Desktop appFree + model costs | ★ 606 | 11d ago | TypeScript | OpenAI API · Claude API |
| NextClaw | 58 · Major gaps | Desktop appFree + model costs | ★ 260 | today | TypeScript | Codex · Claude Code |
| MyAgents | 57 · Major gaps | Desktop appFree + model costs | ★ 918 | 2d ago | TypeScript | Codex · Claude Code · Claude API |
| GenOffice | 82 · Good | Desktop appFree + model costs | ★ 9.1k | today | TypeScript | OpenAI API · Claude API |
How does FollowAgents rate this agent?
Why each dimension lost points
SECURITY.md documents full Electron renderer lockdown (contextIsolation, nodeIntegration:false, sandbox:true), schema-validated IPC, a single safeExternalUrl protocol allowlist gate, an Acorn-parsed constrained AST interpreter for AI layout scripts instead of eval, and hostile-content handling for AI-generated HTML export — solid evidence for least privilege and sensitive data handling (2). However, AI edits mutate documents and insert images/charts without per-action user confirmation, relying on snapshots/diffs and undo, so user_confirmation is 1; external effects (web search, image fetch, Genspark proxy, default telemetry) are disclosed but lack granular opt-out detail, so external_effects 1; rollback mentions version snapshots and diffs but no explicit one-click restore or backup policy, so rollback 1. Dependency security has npm license checks, cargo-deny, SHA-pinned actions, and nanoid overrides, but no SBOM or vulnerability-scanning evidence, so 2. Source attribution is well covered in acknowledgements and third-party notices (2).
CI covers format/lint/typecheck/unit/e2e plus a byte-preservation compatibility gate and fixture-drift check, supporting self-consistency (2). Dependency availability is good: engines pin Node>=22.12 and npm>=10, Rust toolchain and system fonts are explicitly installed in CI (2). Failure messages appear as explicit errors in tests (e.g., 'edited by the user', 'empty points of a native chart cannot be written', '4 blocks'), but no end-user error-message system is shown, so 2.
README targets macOS/Windows/Linux users and developers with clear scenarios (2). Capability boundaries are well stated: local editing vs networked AI, BYOK vs Genspark sign-in, OCR only on macOS/Windows, no published artifacts for Intel/Windows/Linux (2). Trigger precision is weak: AI tool invocation depends on model choice with no strict trigger constraints or misfire safeguards documented, so 1. Environment fit has explicit system requirements and build steps (2).
Information architecture is clear (Apps table, Engine packages, Development, FAQ, Architecture notes) (2). Install notes are thorough, covering dmg/deb/rpm/AppImage and first-launch confirmation (2). Naming is stable and consistent across packages/workspaces (2). Examples and FAQ are rich (2). Known limitations are listed (not notarized, some platforms build-from-source, OCR platform limits) (2). License is Apache-2.0 with a separate enterprise license for ee/, clearly explained (2). Versioning/changelog only shows 0.1.0 and a Releases link, no CHANGELOG file, so 1. Maintenance responsibility names Mainfunc, Inc. and trademark notices, but no governance/maintainer commitment or SLA, and publisher identity is unverified, so 1.
Output usability is test-backed: block-level edits, chart patches, comment threads, and selection freezing are verified (2). Marginal value is clear: local PDF conversion, byte-preserving docx, multi-model BYOK (2). Cost-benefit: free and open-source with local processing reducing cloud cost, but default telemetry and Genspark proxy introduce hidden cost/dependency, so 2.
claim_traceability: README claims partially map to code/tests, but strong claims ('world's first full-featured', 'Word never notices') lack traceable evidence, so 1. cross_source_corroboration: README, SECURITY, CI, and tests corroborate each other, but no independent third-party verification, so 1. fact_inference_separation: documentation mixes facts with marketing language without clearly separating inference from fact, so 1.
- Publisher identity is unverified, and the repository URL in package.json points to genspark-ai/hermesoffice, inconsistent with the given criptogus/HermesOffice — verify provenance.
- Telemetry is enabled by default and AI features default to the Genspark proxy, which may involve data egress; review PRIVACY.md and confirm it can be fully disabled.
- AI edits mutate documents and insert external images/charts without per-action user confirmation; enable snapshots/backups for sensitive documents.
- Only macOS Apple Silicon has published artifacts; other platforms require building from source, and the macOS bundle is not notarized, requiring manual first-launch approval.
- No CHANGELOG file and version only 0.1.0; long-term maintenance and update path are unclear.