spreadsheet-processor

Warn

Audited by Socket on Sep 16, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated spreadsheet-processing purpose is coherent and most dependencies are standard, but the mandatory `recalc.py` executable is not provided or attributable to a verified publisher. That unverifiable execution step makes the skill high risk on install/execution trust even without clear evidence of credential theft or exfiltration.

Confidence: 85%Severity: 75%
SecurityMEDIUM
recalc.py

This module is primarily a LibreOffice headless recalculation wrapper, but it also conditionally writes a LibreOffice Basic macro (Module1.xba) into the user’s LibreOffice profile directory and then invokes it via vnd.sun.star.script. That combination (persistent host modification + Office/LibreOffice macro execution) is a strong security red flag for supply-chain risk because the macro payload can potentially execute arbitrary actions in the LibreOffice process context. The provided fragment is incomplete around macro_content, so the exact payload cannot be verified here; treat this as high-risk and require inspection of the actual macro content and packaging process, ideally in a sandbox.

Confidence: 62%Severity: 72%
Audit Metadata
Analyzed At
Sep 16, 2026, 09:25 AM
Package URL
pkg:socket/skills-sh/qodex-ai%2Fai-agent-skills%2Fspreadsheet-processor%2F@b9ca583c682a3c9b85b8c8383cd36deeb07ff41a0e9bcf17050dcae747d60702
Security Audit — socket — spreadsheet-processor