skills/jr2804/prompts/xlsx/Gen Agent Trust Hub

xlsx

Fail

Audited by Gen Agent Trust Hub on May 21, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The file scripts/soffice.py contains functionality to dynamically generate C source code, compile it into a shared object using gcc, and inject it into the soffice process environment via the LD_PRELOAD environment variable to bypass environment restrictions.
  • [COMMAND_EXECUTION]: The script scripts/recalc.py writes a StarBasic macro (Module1.xba) to the user's local application configuration path for LibreOffice (~/.config/libreoffice or ~/Library/Application Support/LibreOffice) and executes it.
  • [COMMAND_EXECUTION]: Multiple scripts, including scripts/recalc.py, scripts/soffice.py, and scripts/validators/redlining.py, utilize the subprocess module to execute system binaries such as soffice, gcc, git, and timeout.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
May 21, 2026, 08:51 PM
Security Audit — agent-trust-hub — xlsx