A

Is docx safe?

anthropics/skills · scanned Oct 4, 2026

What it says it does

Use this skill whenever the user wants to create, read, edit, or manipulate Word documents (.docx files) or Word templates (.dotx files). Triggers include: any mention of 'Word doc', 'word document', '.docx', '.dotx', or requests to produce professional documents with formatting like tables of contents, headings, page numbers, or letterheads. Also use when extracting or reorganizing content from .docx or .dotx files, inserting or replacing images in documents, performing find-and-replace in Word files, working with tracked changes or comments, or converting content into a polished Word document. If the user asks for a 'report', 'memo', 'letter', 'template', or similar deliverable as a Word or .docx file, use this skill. Do NOT use for PDFs, spreadsheets, Google Docs, or general coding tasks unrelated to document generation.

A
Score 96/100

No significant risks found by the automated scan.

Low · 6
Source
Repository
anthropics/skills/skills/docx
Commit
8a1541c4a3ff
Scanned
Oct 4, 2026
Files checked
40
Stars
180k
License
None declared
Last push
Oct 3, 2026
What it can reach
External domains mentioned anywhere in the skill's files.
openoffice.orgschemas.microsoft.comschemas.openxmlformats.orgwww.anthropic.comwww.w3.org
Findings (6)
Pattern matches are leads, not proof. A finding in documentation is often harmless; one in a script deserves a closer look.
LowRuns shell commandsCode execution

Many legitimate skills run commands. Check that the commands match what the skill says it does.

skills/docx/scripts/accept_changes.py:68

result = subprocess.run(
LowRuns shell commandsCode execution

Many legitimate skills run commands. Check that the commands match what the skill says it does.

skills/docx/scripts/accept_changes.py:99

subprocess.run(
LowRuns shell commandsCode execution

Many legitimate skills run commands. Check that the commands match what the skill says it does.

skills/docx/scripts/office/soffice.py:46

return subprocess.run(["soffice"] + args, env=get_soffice_env(), **kwargs)
LowRuns shell commandsCode execution

Many legitimate skills run commands. Check that the commands match what the skill says it does.

skills/docx/scripts/office/soffice.py:68

subprocess.run(
LowRuns shell commandsCode execution

Many legitimate skills run commands. Check that the commands match what the skill says it does.

skills/docx/scripts/office/validators/redlining.py:192

result = subprocess.run(
LowRuns shell commandsCode execution

Many legitimate skills run commands. Check that the commands match what the skill says it does.

skills/docx/scripts/office/validators/redlining.py:221

result = subprocess.run(
Files scanned (40)
  • skills/docx/LICENSE.txt (1.4 KB)
  • skills/docx/scripts/__init__.py (1 B)
  • skills/docx/scripts/accept_changes.py (4.0 KB)
  • skills/docx/scripts/comment.py (13.7 KB)
  • skills/docx/scripts/merge_runs.py (9.2 KB)
  • skills/docx/scripts/office/helpers/__init__.py (3.3 KB)
  • skills/docx/scripts/office/helpers/pptx_chart.py (5.7 KB)
  • skills/docx/scripts/office/helpers/pptx_slide.py (1.6 KB)
  • skills/docx/scripts/office/helpers/pptx_theme.py (3.4 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/dml-chart.xsd (73.2 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/dml-chartDrawing.xsd (6.8 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/dml-diagram.xsd (50.1 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/dml-lockedCanvas.xsd (624 B)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/dml-main.xsd (148.5 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/dml-picture.xsd (1.2 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/dml-spreadsheetDrawing.xsd (8.7 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/dml-wordprocessingDrawing.xsd (14.4 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/pml.xsd (81.7 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/shared-additionalCharacteristics.xsd (1.2 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/shared-bibliography.xsd (7.2 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/shared-commonSimpleTypes.xsd (6.2 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/shared-customXmlDataProperties.xsd (1.2 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/shared-customXmlSchemaProperties.xsd (880 B)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/shared-documentPropertiesCustom.xsd (2.5 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/shared-documentPropertiesExtended.xsd (3.4 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/shared-documentPropertiesVariantTypes.xsd (7.3 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/shared-math.xsd (22.8 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/shared-relationshipReference.xsd (1.3 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/sml.xsd (236.6 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/vml-main.xsd (25.5 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/vml-officeDrawing.xsd (24.7 KB)
  • skills/docx/scripts/office/schemas/ISO-IEC29500-4_2016/vml-presentationDrawing.xsd (535 B)
  • skills/docx/scripts/office/soffice.py (5.8 KB)
  • skills/docx/scripts/office/validate.py (6.0 KB)
  • skills/docx/scripts/office/validators/__init__.py (336 B)
  • skills/docx/scripts/office/validators/base.py (33.0 KB)
  • skills/docx/scripts/office/validators/docx.py (17.1 KB)
  • skills/docx/scripts/office/validators/pptx.py (15.6 KB)
  • skills/docx/scripts/office/validators/redlining.py (11.0 KB)
  • skills/docx/SKILL.md (6.7 KB)
Add the badge to your README
Shows the current grade and links back to this report. It updates when the skill is rescanned.
SkillsVetted grade A
[![SkillsVetted grade](https://skillsvetted.com/badge/anthropics/docx.svg)](https://skillsvetted.com/skills/anthropics/docx)
Rescan
Pull the latest commit from GitHub and update this listing.
Want a human to check it?

A full review covers what pattern matching can't: intent, logic and behavior in a sandbox.

Request full review