docx-processing-anthropic
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.runto call system utilities includingpandoc,soffice,pdftoppm, andgitfor document conversion, manipulation, and validation tasks. - [COMMAND_EXECUTION]: In
scripts/office/soffice.py, the skill dynamically compiles a C socket shim usinggccand injects it into thesofficeprocess via theLD_PRELOADenvironment variable. This is a technical feature designed to enable document conversion when standard Unix sockets are blocked in sandboxed environments.
Audit Metadata