docx
What this skill does
Manipulate and edit Word documents (.docx and .dotx files), including creating, reading, editing, and working with tracked changes, comments, and document structure.
github/k-dense-ai - Tool Misuse - 33.1k stars
Threat analysis
Skill info
pkg:github/K-Dense-AI/scientific-agent-skills@3956e54?skill=docxAssessments (2)
Tool Misuse
Tool Misuse via local-llm-review
scripts/accept_changes.py
The script uses `subprocess.run` to execute `soffice` with a macro that may be used to manipulate Word documents. While this is legitimate for the purpose of the skill, the use of `subprocess.run` witTool Misuse via local-llm-review
scripts/office/soffice.py
The script uses `subprocess.run` to execute `soffice` with a custom environment. While this is intended to work around sandboxing restrictions, the use of `subprocess.run` with `check=True` and `captuBadge
Add the Anomity scan badge for docx to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of docx? Report an issue or request a rescan.




