Back to skill

Security audit

Xlsx

Security checks for vulnerabilities and agentic risk

Overview

This spreadsheet skill is mostly useful and coherent, but it includes a broader LibreOffice command wrapper and in-place workbook changes that deserve review before installation.

Review before installing. Use this only in a workspace where running local LibreOffice on spreadsheet files is acceptable, keep backups of important workbooks, prefer saving edits to new output files, and avoid using the generic soffice helper for non-spreadsheet document conversion unless you intentionally want that broader capability.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill is presented as spreadsheet-focused, but its documented behavior includes a generic LibreOffice-based recalculation flow that can expand into broader office-document handling. A description-behavior mismatch is dangerous because policy, routing, and user expectations may permit the skill in spreadsheet-only contexts while it actually exposes more general document processing and shell-backed execution surfaces.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/office/soffice.py (reported line 20)May include surrounding context.

python
def get_soffice_env() -> dict:
    env = os.environ.copy()
    env["SAL_USE_VCLPLUGIN"] = "svp"
    return env

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs use of shell commands and file-writing workflows (inspect.py, recalc.py, LibreOffice headless) but declares no explicit tool scope or permission boundaries. That increases the chance an agent will invoke filesystem or shell capabilities more broadly than intended, especially in automated environments where capability declarations are relied upon for sandboxing and policy enforcement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description says to use this skill any time a spreadsheet file is the primary input or output and then expands that to nearly any task involving opening, reading, editing, fixing, creating, converting, cleaning, or restructuring spreadsheet and tabular files. This activation scope is so broad that it lacks clear boundaries for when the skill should not trigger, and it provides no exclusion conditions or negative examples to prevent unintended invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill gives direct instructions for editing and saving spreadsheets, including inserting/deleting rows and columns, without requiring backups, confirmation, or output-to-new-file safeguards. In practice this can cause silent data loss, corruption of formulas, or overwriting user files, which is especially risky for financial models and operational spreadsheets.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This spreadsheet skill exposes a generic LibreOffice subprocess runner that can operate on arbitrary Office document types, not just spreadsheets. In an agent skill context, that broad capability expands the attack surface and enables out-of-scope document handling or conversion workflows that may bypass intended safeguards for spreadsheet-only processing.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module documentation explicitly demonstrates conversion of a non-spreadsheet document (input.docx), which signals and encourages use outside the stated spreadsheet-only purpose of the skill. In an agent environment, examples shape behavior, so this increases the likelihood of the skill being used to process broader document classes than intended.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/office/soffice.py (reported line 27)May include surrounding context.

python
def run_soffice(args: list[str], **kwargs) -> subprocess.CompletedProcess:
    env = get_soffice_env()
    return subprocess.run(["soffice"] + args, env=env, **kwargs)


if __name__ == "__main__":

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/recalc.py (reported line 45)May include surrounding context.

python
def has_gtimeout():
    try:
        subprocess.run(
            ["gtimeout", "--version"], capture_output=True, timeout=1, check=False
        )
        return True

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
83% confidence
Finding

This code launches LibreOffice (soffice) on a user-supplied spreadsheet file, which causes a large external parser and document-processing engine to handle attacker-controlled content. Even without shell=True, this is dangerous in the skill context because malformed or weaponized office files can trigger parser vulnerabilities, excessive resource consumption, or unsafe macro/document behaviors in the external application.

Content

Scanner excerpt · scripts/recalc.py (reported line 96)May include surrounding context.

python
elif platform.system() == "Darwin" and has_gtimeout():
            cmd = ["gtimeout", str(timeout)] + cmd

        result = subprocess.run(
            cmd, capture_output=True, text=True, env=get_soffice_env()
        )

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The section titled 'Corvera Branding' instructs the skill to apply Corvera brand styling when creating spreadsheets for reports or deliverables, which imposes an organization-specific output convention as a default. Since no opt-in, user choice, or clear limitation is provided in this file, this can be a natural-language policy issue if the branding is applied regardless of user preference or project context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.