Chen Word Docx

Security checks across malware telemetry and agentic risk

Overview

The provided artifacts show a purpose-aligned, instruction-only DOCX editing skill with no code, install step, credentials, or background behavior, with only minor metadata/provenance inconsistency to notice.

This appears safe to use as a DOCX-focused instruction skill. Verify the publisher/version if that matters, and work on copies of important Word documents when making edits involving tracked changes, comments, or formatting-sensitive content.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI04: Agentic Supply Chain Vulnerabilities
Info
What this means

A user may want to verify they are installing the intended publisher/version, but the artifacts do not show code execution or hidden behavior.

Why it was flagged

These bundled metadata values differ from the registry values shown for owner, slug, and version, creating a minor provenance/version-identification mismatch. This is not evidence of unsafe behavior because the skill has no executable install or code files.

Skill content
"ownerId": "kn73vp5rarc3b14rc7wjcw8f8580t5d1", "slug": "word-docx", "version": "1.0.2"
Recommendation

Confirm the skill listing, homepage, and publisher details if provenance matters before installing.