docx — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited docx (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
.docx 文件是一个包含 XML 文件的 ZIP 压缩包。
| 任务 | 方法 |
|---|---|
| 读取/分析内容 | pandoc 或解包以获取原始 XML |
| 创建新文档 | 使用 docx-js - 参见下文的“创建新文档” |
| 编辑现有文档 | 解包 → 编辑 XML → 重新打包 - 参见下文的“编辑现有文档” |
旧版的 .doc 文件在编辑前必须进行转换:
python scripts/office/soffice.py --headless --convert-to docx document.doc# 提取带有修订记录的文本
pandoc --track-changes=all document.docx -o output.md
# 访问原始 XML
python scripts/office/unpack.py document.docx unpacked/python scripts/office/soffice.py --headless --convert-to pdf document.docx
pdftoppm -jpeg -r 150 document.pdf page要生成一个接受了所有修订的干净文档(需要 LibreOffice):
python scripts/accept_changes.py input.docx output.docx使用 JavaScript 生成 .docx 文件,然后进行验证。安装:npm install -g docx
const { Document, Packer, Paragraph, TextRun, Table, TableRow, TableCell, ImageRun,
Header, Footer, AlignmentType, PageOrientation, LevelFormat, ExternalHyperlink,
InternalHyperlink, Bookmark, FootnoteReferenceRun, PositionalTab,
PositionalTabAlignment, PositionalTabRelativeTo, PositionalTabLeader,
TabStopType, TabStopPosition, Column, SectionType,
TableOfContents, HeadingLevel, BorderStyle, WidthType, ShadingType,
VerticalAlign, PageNumber, PageBreak } = require('docx');
const doc = new Document({ sections: [{ children: [/* content */] }] });
Packer.toBuffer(doc).then(buffer => fs.writeFileSync("doc.docx", buffer));创建文件后,对其进行验证。如果验证失败,则解包、修复 XML,然后重新打包。
python scripts/office/validate.py doc.docx// 关键:docx-js 默认使用 A4,而非 US Letter
// 为保证结果一致,务必明确设置页面尺寸
sections: [{
properties: {
page: {
size: {
width: 12240, // 8.5 英寸(单位 DXA)
height: 15840 // 11 英寸(单位 DXA)
},
margin: { top: 1440, right: 1440, bottom: 1440, left: 1440 } // 1 英寸页边距
}
},
children: [/* content */]
}]常用页面尺寸(DXA 单位,1440 DXA = 1 英寸):
| 纸张 | 宽度 | 高度 | 内容宽度 (1" 页边距) |
|---|---|---|---|
| US Letter | 12,240 | 15,840 | 9,360 |
| A4 (默认) | 11,906 | 16,838 | 9,026 |
横向: docx-js 内部会交换宽高,因此传入纵向尺寸,让它处理交换:
size: {
width: 12240, // 将短边作为宽度传入
height: 15840, // 将长边作为高度传入
orientation: PageOrientation.LANDSCAPE // docx-js 会在 XML 中交换它们
},
// 内容宽度 = 15840 - 左边距 - 右边距 (使用长边)使用 Arial 作为默认字体(通用支持)。标题保持黑色以提高可读性。
const doc = new Document({
styles: {
default: { document: { run: { font: "Arial", size: 24 } } }, // 12pt 默认
paragraphStyles: [
// 重要:使用确切的 ID 来覆盖内置样式
{ id: "Heading1", name: "Heading 1", basedOn: "Normal", next: "Normal", quickFormat: true,
run: { size: 32, bold: true, font: "Arial" },
paragraph: { spacing: { before: 240, after: 240 }, outlineLevel: 0 } }, // outlineLevel 是目录所必需的
{ id: "Heading2", name: "Heading 2", basedOn: "Normal", next: "Normal", quickFormat: true,
run: { size: 28, bold: true, font: "Arial" },
paragraph: { spacing: { before: 180, after: 180 }, outlineLevel: 1 } },
]
},
sections: [{
children: [
new Paragraph({ heading: HeadingLevel.HEADING_1, children: [new TextRun("Title")] }),
]
}]
});// ❌ 错误 - 切勿手动插入项目符号字符
new Paragraph({ children: [new TextRun("• Item")] }) // 错误
new Paragraph({ children: [new TextRun("\u2022 Item")] }) // 错误
// ✅ 正确 - 使用带 LevelFormat.BULLET 的编号配置
const doc = new Document({
numbering: {
config: [
{ reference: "bullets",
levels: [{ level: 0, format: LevelFormat.BULLET, text: "•", alignment: AlignmentType.LEFT,
style: { paragraph: { indent: { left: 720, hanging: 360 } } } }] },
{ reference: "numbers",
levels: [{ level: 0, format: LevelFormat.DECIMAL, text: "%1.", alignment: AlignmentType.LEFT,
style: { paragraph: { indent: { left: 720, hanging: 360 } } } }] },
]
},
sections: [{
children: [
new Paragraph({ numbering: { reference: "bullets", level: 0 },
children: [new TextRun("Bullet item")] }),
new Paragraph({ numbering: { reference: "numbers", level: 0 },
children: [new TextRun("Numbered item")] }),
]
}]
});
// ⚠️ 每个 reference 创建独立的编号
// 相同 reference = 继续编号 (1,2,3 然后 4,5,6)
// 不同 reference = 重新开始 (1,2,3 然后 1,2,3)关键:表格需要双重宽度设置 - 在表格上设置 columnWidths,同时在每个单元格上设置 width。缺少任一设置,表格在某些平台上会渲染不正确。
// 关键:始终设置表格宽度以确保一致的渲染
// 关键:使用 ShadingType.CLEAR (而非 SOLID) 以防止黑色背景
const border = { style: BorderStyle.SINGLE, size: 1, color: "CCCCCC" };
const borders = { top: border, bottom: border, left: border, right: border };
new Table({
width: { size: 9360, type: WidthType.DXA }, // 始终使用 DXA (百分比在 Google Docs 中会出问题)
columnWidths: [4680, 4680], // 必须等于表格宽度 (DXA: 1440 = 1 英寸)
rows: [
new TableRow({
children: [
new TableCell({
borders,
width: { size: 4680, type: WidthType.DXA }, // 同样在每个单元格上设置
shading: { fill: "D5E8F0", type: ShadingType.CLEAR }, // CLEAR 而非 SOLID
margins: { top: 80, bottom: 80, left: 120, right: 120 }, // 单元格内边距 (不计入宽度)
children: [new Paragraph({ children: [new TextRun("Cell")] })]
})
]
})
]
})表格宽度计算:
始终使用 WidthType.DXA — WidthType.PERCENTAGE 在 Google Docs 中会出问题。
// 表格宽度 = columnWidths 之和 = 内容宽度
// US Letter, 1" 页边距: 12240 - 2880 = 9360 DXA
width: { size: 9360, type: WidthType.DXA },
columnWidths: [7000, 2360] // 必须等于表格宽度宽度规则:
WidthType.PERCENTAGE (与 Google Docs 不兼容)width 必须等于 columnWidths 的总和width 必须与对应的 columnWidth 匹配margins 是内部填充 - 它们会减少内容区域,而不会增加单元格宽度// 关键:type 参数是必需的
new Paragraph({
children: [new ImageRun({
type: "png", // 必需: png, jpg, jpeg, gif, bmp, svg
data: fs.readFileSync("image.png"),
transformation: { width: 200, height: 150 },
altText: { title: "Title", description: "Desc", name: "Name" } // 三者都必需
})]
})// 关键:PageBreak 必须在 Paragraph 内部
new Paragraph({ children: [new PageBreak()] })
// 或者使用 pageBreakBefore
new Paragraph({ pageBreakBefore: true, children: [new TextRun("New page")] })// 外部链接
new Paragraph({
children: [new ExternalHyperlink({
children: [new TextRun({ text: "Click here", style: "Hyperlink" })],
link: "https://example.com",
})]
})
// 内部链接 (书签 + 引用)
// 1. 在目标位置创建书签
new Paragraph({ heading: HeadingLevel.HEADING_1, children: [
new Bookmark({ id: "chapter1", children: [new TextRun("Chapter 1")] }),
]})
// 2. 链接到它
new Paragraph({ children: [new InternalHyperlink({
children: [new TextRun({ text: "See Chapter 1", style: "Hyperlink" })],
anchor: "chapter1",
})]})const doc = new Document({
footnotes: {
1: { children: [new Paragraph("Source: Annual Report 2024")] },
2: { children: [new Paragraph("See appendix for methodology")] },
},
sections: [{
children: [new Paragraph({
children: [
new TextRun("Revenue grew 15%"),
new FootnoteReferenceRun(1),
new TextRun(" using adjusted metrics"),
new FootnoteReferenceRun(2),
],
})]
}]
});// 在同一行右对齐文本 (例如,标题对面的日期)
new Paragraph({
children: [
new TextRun("Company Name"),
new TextRun("\tJanuary 2025"),
],
tabStops: [{ type: TabStopType.RIGHT, position: TabStopPosition.MAX }],
})
// 点状前导符 (例如,目录样式)
new Paragraph({
children: [
new TextRun("Introduction"),
new TextRun({ children: [
new PositionalTab({
alignment: PositionalTabAlignment.RIGHT,
relativeTo: PositionalTabRelativeTo.MARGIN,
leader: PositionalTabLeader.DOT,
}),
"3",
]}),
],
})// 等宽分栏
sections: [{
properties: {
column: {
count: 2, // 分栏数
space: 720, // 栏间距,单位 DXA (720 = 0.5 英寸)
equalWidth: true,
separate: true, // 栏间垂直线
},
},
children: [/* 内容会自然地在各栏间流动 */]
}]
// 自定义宽度分栏 (equalWidth 必须为 false)
sections: [{
properties: {
column: {
equalWidth: false,
children: [
new Column({ width: 5400, space: 720 }),
new Column({ width: 3240 }),
],
},
},
children: [/* content */]
}]使用 type: SectionType.NEXT_COLUMN 的新节来强制分栏。
// 关键:标题必须仅使用 HeadingLevel - 不能使用自定义样式
new TableOfContents("Table of Contents", { hyperlink: true, headingStyleRange: "1-3" })sections: [{
properties: {
page: { margin: { top: 1440, right: 1440, bottom: 1440, left: 1440 } } // 1440 = 1 英寸
},
headers: {
default: new Header({ children: [new Paragraph({ children: [new TextRun("Header")] })] })
},
footers: {
default: new Footer({ children: [new Paragraph({
children: [new TextRun("Page "), new TextRun({ children: [PageNumber.CURRENT] })]
})] })
},
children: [/* content */]
}]width,长边作为 height 传入,并设置 orientation: PageOrientation.LANDSCAPELevelFormat.BULLETWidthType.PERCENTAGE (在 Google Docs 中会出问题)columnWidths 数组和单元格 width,两者必须匹配margins: { top: 80, bottom: 80, left: 120, right: 120 } 以获得可读的内边距border: { bottom: { style: BorderStyle.SINGLE, size: 6, color: "2E75B6", space: 1 } } 代替。对于两栏页脚,使用制表位(见“制表位”部分),而非表格按顺序执行所有 3 个步骤。
python scripts/office/unpack.py document.docx unpacked/提取 XML,进行格式美化,合并相邻的 run,并将智能引号转换为 XML 实体(“ 等),以便它们在编辑后能保留。使用 --merge-runs false 跳过 run 合并。
编辑 unpacked/word/ 目录下的文件。有关模式,请参阅下面的 XML 参考。
使用 "Claude" 作为作者来进行修订和批注,除非用户明确要求使用其他名称。
直接使用编辑工具进行字符串替换。不要编写 Python 脚本。 脚本会引入不必要的复杂性。编辑工具能精确显示被替换的内容。
关键:对新内容使用智能引号。 当添加带有撇号或引号的文本时,使用 XML 实体来生成智能引号:
<!-- 使用这些实体以获得专业的排版效果 -->
<w:t>Here’s a quote: “Hello”</w:t>| 实体 | 字符 |
|---|---|
‘ | ‘ (左单引号) |
’ | ’ (右单引号 / 撇号) |
“ | “ (左双引号) |
” | ” (右双引号) |
添加批注: 使用 comment.py 来处理多个 XML 文件中的样板代码(文本必须是预先转义的 XML):
python scripts/comment.py unpacked/ 0 "Comment text with & and ’"
python scripts/comment.py unpacked/ 1 "Reply text" --parent 0 # 回复批注 0
python scripts/comment.py unpacked/ 0 "Text" --author "Custom Author" # 自定义作者名然后在 document.xml 中添加标记(见 XML 参考中的“批注”)。
python scripts/office/pack.py unpacked/ output.docx --original document.docx使用自动修复进行验证,压缩 XML,并创建 DOCX。使用 --validate false 跳过验证。
自动修复将解决:
durableId >= 0x7FFFFFFF (重新生成有效的 ID)<w:t> 缺少 xml:space="preserve"自动修复无法解决:
<w:del>...<w:ins>... 作为同级元素替换整个 <w:r>...</w:r> 块。不要在 run 内部注入修订标记。<w:rPr> 块复制到你的修订 run 中,以保持粗体、字号等格式。<w:pStyle>, <w:numPr>, <w:spacing>, <w:ind>, <w:jc>, <w:rPr> 最后<w:t> 添加 xml:space="preserve"00AB1234)插入:
<w:ins w:id="1" w:author="Claude" w:date="2025-01-01T00:00:00Z">
<w:r><w:t>inserted text</w:t></w:r>
</w:ins>删除:
<w:del w:id="2" w:author="Claude" w:date="2025-01-01T00:00:00Z">
<w:r><w:delText>deleted text</w:delText></w:r>
</w:del>在 `<w:del>` 内部:使用 <w:delText> 代替 <w:t>,使用 <w:delInstrText> 代替 <w:instrText>。
最小化编辑 - 只标记变化的部分:
<!-- 将 "30 days" 改为 "60 days" -->
<w:r><w:t>The term is </w:t></w:r>
<w:del w:id="1" w:author="Claude" w:date="...">
<w:r><w:delText>30</w:delText></w:r>
</w:del>
<w:ins w:id="2" w:author="Claude" w:date="...">
<w:r><w:t>60</w:t></w:r>
</w:ins>
<w:r><w:t> days.</w:t></w:r>删除整个段落/列表项 - 当移除段落的所有内容时,同时将段落标记标记为已删除,以便它与下一段落合并。在 <w:pPr><w:rPr> 内添加 <w:del/>:
<w:p>
<w:pPr>
<w:numPr>...</w:numPr> <!-- 如果存在,则是列表编号 -->
<w:rPr>
<w:del w:id="1" w:author="Claude" w:date="2025-01-01T00:00:00Z"/>
</w:rPr>
</w:pPr>
<w:del w:id="2" w:author="Claude" w:date="2025-01-01T00:00:00Z">
<w:r><w:delText>Entire paragraph content being deleted...</w:delText></w:r>
</w:del>
</w:p>如果没有 <w:pPr><w:rPr> 中的 <w:del/>,接受修订后会留下一个空段落/列表项。
拒绝另一位作者的插入 - 在他们的插入内部嵌套删除:
<w:ins w:author="Jane" w:id="5">
<w:del w:author="Claude" w:id="10">
<w:r><w:delText>their inserted text</w:delText></w:r>
</w:del>
</w:ins>恢复另一位作者的删除 - 在后面添加插入(不要修改他们的删除):
<w:del w:author="Jane" w:id="5">
<w:r><w:delText>deleted text</w:delText></w:r>
</w:del>
<w:ins w:author="Claude" w:id="10">
<w:r><w:t>deleted text</w:t></w:r>
</w:ins>运行 comment.py(见第 2 步)后,向 document.xml 添加标记。对于回复,使用 --parent 标志并将标记嵌套在父标记内。
关键:`<w:commentRangeStart>` 和 `<w:commentRangeEnd>` 是 `<w:r>` 的同级元素,绝不能在 `<w:r>` 内部。
<!-- 批注标记是 w:p 的直接子元素,绝不在 w:r 内部 -->
<w:commentRangeStart w:id="0"/>
<w:del w:id="1" w:author="Claude" w:date="2025-01-01T00:00:00Z">
<w:r><w:delText>deleted</w:delText></w:r>
</w:del>
<w:r><w:t> more text</w:t></w:r>
<w:commentRangeEnd w:id="0"/>
<w:r><w:rPr><w:rStyle w:val="CommentReference"/></w:rPr><w:commentReference w:id="0"/></w:r>
<!-- 批注 0 及其内部嵌套的回复 1 -->
<w:commentRangeStart w:id="0"/>
<w:commentRangeStart w:id="1"/>
<w:r><w:t>text</w:t></w:r>
<w:commentRangeEnd w:id="1"/>
<w:commentRangeEnd w:id="0"/>
<w:r><w:rPr><w:rStyle w:val="CommentReference"/></w:rPr><w:commentReference w:id="0"/></w:r>
<w:r><w:rPr><w:rStyle w:val="CommentReference"/></w:rPr><w:commentReference w:id="1"/></w:r>word/media/word/_rels/document.xml.rels 添加关系:<Relationship Id="rId5" Type=".../image" Target="media/image1.png"/>[Content_Types].xml 添加内容类型:<Default Extension="png" ContentType="image/png"/><w:drawing>
<wp:inline>
<wp:extent cx="914400" cy="914400"/> <!-- EMU 单位:914400 = 1 英寸 -->
<a:graphic>
<a:graphicData uri=".../picture">
<pic:pic>
<pic:blipFill><a:blip r:embed="rId5"/></pic:blipFill>
</pic:pic>
</a:graphicData>
</a:graphic>
</wp:inline>
</w:drawing>npm install -g docx (新文档)scripts/office/soffice.py 为沙盒环境自动配置)pdftoppm 用于图片处理~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.