docling-word

Pass

Audited by Gen Agent Trust Hub on Apr 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/docling_word_to_markdown.py performs system calls to uv and docling using the subprocess.run method. These calls use argument lists, which is a secure practice that prevents shell injection vulnerabilities.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the docling package using uv tool install. This is an expected and functional part of the skill's operation for document processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 13, 2026, 02:37 PM