xlsx

Warn

Audited by Socket on Sep 27, 2026

4 alerts found:

SecurityAnomalyx3
SecurityMEDIUM
recalc.py

This module is primarily a LibreOffice headless recalculation wrapper, but it also conditionally writes a LibreOffice Basic macro (Module1.xba) into the user’s LibreOffice profile directory and then invokes it via vnd.sun.star.script. That combination (persistent host modification + Office/LibreOffice macro execution) is a strong security red flag for supply-chain risk because the macro payload can potentially execute arbitrary actions in the LibreOffice process context. The provided fragment is incomplete around macro_content, so the exact payload cannot be verified here; treat this as high-risk and require inspection of the actual macro content and packaging process, ideally in a sandbox.

Confidence: 62%Severity: 72%
AnomalyLOW
scripts/recalc.py

This module is primarily a LibreOffice-driven formula recalculation tool, but it also installs (writes) a persistent LibreOffice Basic macro into a user profile directory and then triggers that macro via a soffice script URL. Because the actual RECALCULATE_MACRO payload is not included in the provided fragment (and get_soffice_env is external), the code cannot be confirmed as harmless; the macro could be leveraged for sabotage or arbitrary actions depending on its content.

Confidence: 62%Severity: 60%
AnomalyLOW
scripts/office/soffice.py

A wrapper launches soffice and, when Unix sockets are unavailable, writes C source to a temporary file, compiles it with gcc, and injects the resulting shared library into soffice via LD_PRELOAD. This pattern enables arbitrary native code execution inside the trusted application. The exact payload source (_SHIM_SOURCE) is not provided in the available fragment, so the specific malicious behavior cannot be fully verified from the excerpt.

Confidence: 62%Severity: 83%
AnomalyLOW
scripts/office/unpack.py

No clear evidence of intentional malware, tracking, credential theft, or network-based exfiltration in this fragment. The primary security weakness is use of zipfile.ZipFile.extractall(output_path) on an untrusted Office ZIP without validating member paths, enabling potential ZIP Slip/path traversal and arbitrary file write outside the chosen output directory. Additional risk could be introduced by the unseen DOCX helper functions, but that behavior is not assessable from this module alone.

Confidence: 72%Severity: 64%
Audit Metadata
Analyzed At
Sep 27, 2026, 06:54 PM
Package URL
pkg:socket/skills-sh/organvm-iv-taxis%2Fa-i--skills%2Fxlsx%2F@8c172560f34db6e9223dcedb70b69a5f3ff2d695ad8bfc7d08eecb20b228f1c0
Security Audit — socket — xlsx