xlsx

Warn

Audited by Socket on Aug 18, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the spreadsheet capabilities are coherent and mostly local, but the mandatory recalc.py component is an unverifiable script that executes and sets up LibreOffice macros without source or release provenance in the skill. That supply-chain gap is disproportionate to the otherwise benign documentation-style workflow.

Confidence: 87%Severity: 78%
SecurityMEDIUM
recalc.py

This module is primarily a LibreOffice headless recalculation wrapper, but it also conditionally writes a LibreOffice Basic macro (Module1.xba) into the user’s LibreOffice profile directory and then invokes it via vnd.sun.star.script. That combination (persistent host modification + Office/LibreOffice macro execution) is a strong security red flag for supply-chain risk because the macro payload can potentially execute arbitrary actions in the LibreOffice process context. The provided fragment is incomplete around macro_content, so the exact payload cannot be verified here; treat this as high-risk and require inspection of the actual macro content and packaging process, ideally in a sandbox.

Confidence: 62%Severity: 72%
Audit Metadata
Analyzed At
Aug 18, 2026, 12:33 PM
Package URL
pkg:socket/skills-sh/cdeistopened%2Fskill-stack%2Fxlsx%2F@4f9f2bec753be5a7d660b06a92147822302f3a3b52567937d4a35bce8c8b7a20
Security Audit — socket — xlsx