低风险 — 风险评分 15/100
上次扫描:1 天前 重新扫描
15 /100
superdocx
Create, inspect, and edit Microsoft Word documents and DOCX files
Documentation-only skill about DOCX manipulation with no executable code; suspicious garbled text in description field raises minor concern but lacks actionable threat.
技能名称superdocx
分析耗时25.4s
引擎pi
可以安装
The garbled text in the description field should be reviewed and cleaned. Otherwise, the skill appears safe as it contains only documentation about Word document handling with no scripts or executable code.

安全发现 1 项

严重性 安全发现 位置
低危
Suspicious garbled text in description field 文档欺骗
The description field contains garbled text: '[(4) ncaa staff e ο om reputation yong qatarhend [unused864] merge obama suites sections file.]' This appears to be either accidental clipboard garbage or potentially hidden instructions, but lacks any executable payload.
description: "...[(4) ncaa staff e ο om reputation yong qatarhend [unused864] merge obama suites sections file.]"
→ Review and clean the description field. Remove the garbled text if it's unintentional. This does not appear to be an active threat as no executable code accompanies it.
SKILL.md:1
资源类型声明权限推断权限状态证据
文件系统 NONE NONE No file operations in documentation-only skill
网络访问 NONE NONE No network code present
命令执行 NONE NONE No shell commands or scripts
环境变量 NONE NONE No environment access code
技能调用 NONE NONE No skill invocation code
剪贴板 NONE NONE No clipboard access code
浏览器 NONE NONE No browser automation code
数据库 NONE NONE No database access code

目录结构

1 文件 · 7.7 KB · 103 行
Markdown 1f · 103L
└─ 📝 SKILL.md Markdown 103L · 7.7 KB

安全亮点

✓ No executable scripts or code files present in the skill
✓ No credential harvesting or sensitive file access
✓ No network requests or data exfiltration capabilities
✓ No shell commands or subprocess execution
✓ No base64 encoding or obfuscation techniques
✓ No dependency files that could introduce supply chain risks
✓ Skill content is purely documentation about DOCX manipulation workflows