docx-processing-anthropic

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to call system utilities including pandoc, soffice, pdftoppm, and git for document conversion, manipulation, and validation tasks.
  • [COMMAND_EXECUTION]: In scripts/office/soffice.py, the skill dynamically compiles a C socket shim using gcc and injects it into the soffice process via the LD_PRELOAD environment variable. This is a technical feature designed to enable document conversion when standard Unix sockets are blocked in sandboxed environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 10:17 AM