docx

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The fragment is consistent with its stated purpose of DOCX creation/editing and analysis, including OOXML access and redlining workflows. It relies on standard external tools rather than hidden or credential-stealing mechanisms. While it expands automation surface via multiple tools, there is no evidence of malicious payloads. Recommended mitigations include version pinning, integrity verification for tools, and enforcing least-privilege access to reduce risk in automated deployment environments.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 26, 2026, 05:52 AM
Package URL
pkg:socket/skills-sh/K-Dense-AI%2Fclaude-scientific-writer%2Fdocx%2F@d402386a781e386f8ecd9a264568581a2af82b9b