xlsx
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/office/soffice.pyexecutes the systemgcccompiler to build a shared library from source code embedded within the script as a hardcoded string.\n- [COMMAND_EXECUTION]: The skill invokes external binaries, includingsoffice(LibreOffice) for spreadsheet recalculation andgitfor comparing document text content during validation.\n- [REMOTE_CODE_EXECUTION]: The scriptscripts/office/soffice.pyuses theLD_PRELOADenvironment variable to perform process injection by loading a self-compiled shared library into the LibreOffice execution environment to manage AF_UNIX socket restrictions.
Audit Metadata