xlsx

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/office/soffice.py

The file drinks a high-risk pattern where C code is written at runtime, compiled with gcc, and preloaded into the soffice process via LD_PRELOAD. Because the _SHIM_SOURCE is not provided, the exact payload cannot be confirmed; therefore, the code should be reviewed in isolation and subjected to rigorous runtime validation and integrity checks before use.

Confidence: 62%Severity: 78%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/anthropics%2Fskills%2Fxlsx%2F@6c80f7a4deecfcb94a22c7181e8fc09166d109aba2454b8ebeac51adf179588c
Security Audit — socket — xlsx