docx

Fail

Audited by Socket on Aug 19, 2026

3 alerts found:

SecurityMalwareAnomaly
SecurityMEDIUM
scripts/accept_changes.py

This module is a document-processing utility that performs headless LibreOffice execution by installing and running a LibreOffice Basic macro from a runtime-writable profile in /tmp. The wrapper itself shows no network access or credential theft, but it provides a strong code-execution primitive (macro write + macro execution via UNO script). Because the macro payload (ACCEPT_CHANGES_MACRO) is not present in the provided fragment, its behavior cannot be verified; if that payload were malicious or tampered, the impact could be substantial within the LibreOffice execution context. Additionally, timeout handling may misreport success, which can undermine output integrity.

Confidence: 45%Severity: 70%
MalwareHIGH
scripts/office/soffice.py

This wrapper executes `soffice` with environment-variable customization and, when Unix sockets are unavailable, writes C source to `/tmp`, compiles it with `gcc`, and injects the resulting shared library into `soffice` via `LD_PRELOAD`. That LD_PRELOAD + runtime compilation pattern is highly suspicious and can enable arbitrary native code execution inside a trusted third-party application. The provided fragment is truncated (the actual `_SHIM_SOURCE` payload is missing), so the true maliciousness cannot be verified from this module excerpt alone; security should be treated as high-risk pending inspection of the shim code.

Confidence: 62%Severity: 83%
AnomalyLOW
scripts/office/unpack.py

No clear evidence of intentional malware, tracking, credential theft, or network-based exfiltration in this fragment. The primary security weakness is use of zipfile.ZipFile.extractall(output_path) on an untrusted Office ZIP without validating member paths, enabling potential ZIP Slip/path traversal and arbitrary file write outside the chosen output directory. Additional risk could be introduced by the unseen DOCX helper functions, but that behavior is not assessable from this module alone.

Confidence: 72%Severity: 64%
Audit Metadata
Analyzed At
Aug 19, 2026, 07:45 PM
Package URL
pkg:socket/skills-sh/bighardperson%2Fcomputer-science-skills-collection%2Fdocx%2F@708172b97e9c2c7215866dcec9b92ca1310cdef11c990531173558d491949acb
Security Audit — socket — docx