xlsx

Warn

Audited by Socket on Aug 18, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/office/soffice.py

The file drinks a high-risk pattern where C code is written at runtime, compiled with gcc, and preloaded into the soffice process via LD_PRELOAD. Because the _SHIM_SOURCE is not provided, the exact payload cannot be confirmed; therefore, the code should be reviewed in isolation and subjected to rigorous runtime validation and integrity checks before use.

Confidence: 62%Severity: 78%
Audit Metadata
Analyzed At
Aug 18, 2026, 01:41 AM
Package URL
pkg:socket/skills-sh/practicalswan%2Fagent-skills%2Fxlsx%2F@5a55d73853fe179c45119c7943601b692ff3c547966a74770711d1de39b19834
Security Audit — socket — xlsx