design-export-repair

Warn

Audited by Socket on Aug 10, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/soffice.py

This module is primarily a headless LibreOffice PDF converter, but it contains a highly sensitive native-code injection mechanism: it can write C source to a temporary directory, compile it at runtime with gcc, and then inject the resulting shared library into the soffice subprocess via LD_PRELOAD. The contents/intent of the shim (_SHIM_SOURCE) are not visible in the provided snippet, so benign vs malicious behavior cannot be confirmed from this fragment alone; however, the execution primitive (LD_PRELOAD of a runtime-compiled library) is inherently high-risk and should be treated as a potential supply-chain/sandbox-evasion/tampering vector pending full review of the actual shim source and build provenance.

Confidence: 55%Severity: 85%
Audit Metadata
Analyzed At
Aug 10, 2026, 02:35 PM
Package URL
pkg:socket/skills-sh/onewave-ai%2Fclaude-skills%2Fdesign-export-repair%2F@58e0ba35a5c4dc854928038722acd10a1df6dbf875154fe2c2a3e3ededc57f40
Security Audit — socket — design-export-repair