docx

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN in purpose and data flow, but HIGH security risk from the unverifiable vendored Validator.dll. The skill is internally consistent for DOCX work and shows no credential harvesting or external exfiltration, yet the binary validator is a black-box executable that materially raises supply-chain risk.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Apr 4, 2026, 01:52 AM
Package URL
pkg:socket/skills-sh/ming-kang%2FSkills%2Fdocx%2F@d7f4c046a2114c32548d5e385592ba8e83bb9a39