Security audit
Superdoc
Security checks across malware telemetry and agentic risk
Overview
The skill is a straightforward DOCX editing guide with normal local file and npm setup actions, and the artifacts do not show hidden credentials, persistence, exfiltration, or destructive behavior.
This appears reasonable for a DOCX manipulation skill. Before using it, verify the SuperDoc npm package/source, consider pinning dependency versions, and make sure the agent only reads and writes document paths you approve.
VirusTotal
66/66 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
