ClawAudit verdict
docx
docx1
Both reads and writes files
The skill provides capabilities to create, read, edit, and manipulate Word documents (.docx) but does not demonstrate any concrete malicious behavior.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
What it does
These are capability combinations: each listed behavior occurs in the skill, but ClawAudit detects co-occurrence โ it does not verify that one flows into another. Read the code to confirm a live chain.
Both reads and writes files โ verify scope is limited to intended directories
LLM06 ยท ASI02
Permission integrity
file_read+write
Findings (4)
File write/delete operation
SKILL.md ยท code
subprocess execution โ runs system commands from Python
scripts/accept_changes.py ยท prose ยท downgraded ยท subprocess.run(
File read operation
SKILL.md ยท code
Python shutil file operation โ copies/moves/deletes files
scripts/comment.py ยท prose ยท downgraded ยท shutil.copy(
Why the tier is capped
Execution sink present in raw bytes (Hard Floor: class D). Final tier capped at Caution โ cannot be lifted by any downgrade, example-payload opt-in, or allowlist.
Permissions & capabilities
No declared permissions โ minimal attack surface.
file_readfile_write Thanks โ recorded.