You can audit document metadata with an AI agent by asking three precise questions, and the agent answers them by reading the files locally through GroupDocs.Metadata.Mcp. A typical first prompt is:

Who is listed as author and last-modified-by across the files in this folder, and which company name do they carry?

The step-by-step version with config and troubleshooting is in the documentation: How to audit document metadata with an AI agent.

Why does a metadata audit need a tool and not just a model?

A language model cannot see metadata. It sees the text you paste, and the author field, the company name and the GPS coordinates are not in that text. An agent that answers “who wrote this?” without calling a tool is guessing, and the guess sounds confident. GroupDocs.Metadata.Mcp is an MCP server that gives Claude, Cursor, GitHub Copilot, VS Code and Windsurf the actual properties of a file: the agent calls a tool, receives JSON, and reports what is there. The files stay in a folder on your machine; only the properties travel to the model.

The three questions below are the ones that explain most privacy surprises. Each works as a standalone prompt.

Question 1: who is named as the author?

Who is listed as author and last-modified-by across the files in this folder?

The agent calls search_metadata with a filter, which returns only the matching properties instead of the whole property set. The tool description says to use it “when the user asks about a SPECIFIC property rather than the whole set”. Filters are category (for example person), nameContains and valueContains, all case-insensitive. The result is a JSON object with count and a properties array of name, value and category.

Why it matters: the author field often holds a real person’s name, and last-modified-by sometimes names a former employee. Neither shows on the page.

Question 2: which company is written into the file?

Does any property in these files still contain the old company name?

This is search_metadata again, with valueContains set to the name. One call per file, and a count of 0 means no match. The company field is frequently inherited from a template, so a document written today can still carry the name of a previous employer. When you need the complete picture of one file rather than a filtered view, the agent uses read_metadata, which returns every property as JSON (the first 5 in evaluation mode): author, title, dates and custom properties.

Question 3: do these photos carry GPS coordinates?

Which of these photos have GPS coordinates? Where?

The search_metadata category gps answers it directly. In evaluation mode EXIF GPS data is unavailable, so a count of 0 proves nothing; check get_license_status first. A photo taken at home and published as-is is the standard example of a location leak, and an audit prompt is faster than opening each image’s properties by hand. If the files are not images, get_document_info gives a lightweight check of type, size, page count and encryption status without listing properties.

Example session (abridged)

You:    Does any property in contract-2024.docx still contain "Northwind"?
Agent:  [calls search_metadata: valueContains = "Northwind"]
Agent:  1 match. Company = "Northwind Traders" (category: corporate).

This is an illustration of the flow, not a captured screenshot. The tool names and the shape of the reply follow the tools reference.

What the audit cannot tell you in evaluation mode

Without a license the server runs in evaluation mode, and the documented limit is exact: only the first 5 document properties are readable, and XMP and EXIF are partly unavailable. XMP exposes only its first two schemes, and for EXIF the GPS data and the image thumbnail are not available. The response does not mention this, so an audit that says “nothing sensitive found” may simply have stopped reading. For a compliance check, an audit under evaluation is incomplete by design.

Before you trust any result, ask:

What is the license status of the metadata server?

The agent calls get_license_status, which reports the mode as evaluation, licensed or metered and never modifies anything. A free 30-day temporary license is available from GroupDocs for full functionality.

Frequently asked questions

Can Claude check a PDF for hidden author information without uploading it? Yes, when GroupDocs.Metadata.Mcp runs on your machine. The client starts the server as a local process over stdio, the file is read from your storage folder, and only the returned properties reach the model.

How do I find hidden metadata in PDF and DOCX files for a document metadata compliance check? Ask the agent to read or search each file with read_metadata or search_metadata, and keep a record of the license mode from get_license_status. A compliance check made in evaluation mode is incomplete, because only 5 properties are readable.

Why does my audit show only a few properties? You are probably in evaluation mode, which returns only the first 5 document properties. Check get_license_status and apply a license file or metered keys.

Set it up

Run the server with Docker or with the .NET 10 SDK:

dnx GroupDocs.Metadata.Mcp --yes

Set GROUPDOCS_MCP_STORAGE_PATH to the folder that holds the files, then register the server in your client. Per-client configuration is in the documentation.

Go deeper