Back to skill

Security audit

xlsx

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a spreadsheet helper, but it uses under-disclosed LibreOffice profile changes, native LD_PRELOAD shims, and bundled non-spreadsheet document tooling that deserve review before installation.

Install only if you are comfortable with a spreadsheet skill that can run LibreOffice, write files, modify your LibreOffice macro profile, and compile/use a native shim in some Linux sandboxed environments. Avoid using it on untrusted Office files or systems with important existing LibreOffice macros unless those behaviors are fixed or isolated.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/office/soffice.py:56
Finding

Predictable LD_PRELOAD Shim Path Enables Local Arbitrary Code Execution

Content
View full analysis
dict: env = os.environ.copy() if platform.system() == "Linux": env["SAL_USE_VCLPLUGIN"] = "svp" if _needs_shim(): shim = _ensure_shim() env["LD_PRELOAD"] = str(shim) return env _SHIM_SO = Path(tempfile.gettempdir()) / "lo_socket_shim.so" def _ensure_shim() -> Path: if _SHIM_SO.exists(): return _SHIM_SO src = Path(tempfile.gettempdir()) / "lo_socket_shim.c" src.write_text(_SHIM_SOURCE) subprocess.run( ["gcc", "-shared", "-fPIC", "-o", str(_SHIM_SO), str(src), "-ldl"], check=True, capture_output=True, ) src.unlink() return _SHIM_SO ``` ### Technical Analysis The code stores the compiled native shim at a predictable, system-wide temporary path such as `/tmp/lo_socket_shim.so`. If that path already exists, `_ensure_shim()` accepts it without validating: - File ownership - File permissions - Whether it is a regular file or symbolic link - Its cryptographic digest or expected contents - Whether it was created by the current process When Unix-domain sockets are unavailable, `get_soffice_env()` assigns this path to `LD_PRELOAD`. The dynamic linker consequently loads the referenced library before starting LibreOffice. A malicious shared library can execute arbitrary native code through a constructor before the legitimate program begins. The implementation also has a time-of-check/time-of-use race between the existence check and compilation. Predictable handling of `lo_socket_shim.c` presents an additional collision and symlink risk. ### Attack Path 1. A local attacker with access to the shared temporary directory prepares a malicious shared object containing a constructor that executes attacker ...[truncated 1130 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/recalc.py:53
Finding

Spreadsheet Recalculation Overwrites a Persistent Global LibreOffice Macro

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/office/unpack.py:51
Finding

Unbounded OOXML Archive Extraction Enables Resource-Exhaustion Attacks

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (48)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Even within the visible skill text, the workflow authorizes generic shell execution of Python scripts and LibreOffice/soffice-based recalculation. If the implementation permits arbitrary soffice commands or uses gcc/LD_PRELOAD-style shims as the finding suggests, that would materially exceed the declared spreadsheet-editing purpose and create a command-execution surface under the guise of benign file processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Even within the visible skill text, the workflow authorizes generic shell execution of Python scripts and LibreOffice/soffice-based recalculation. If the implementation permits arbitrary soffice commands or uses gcc/LD_PRELOAD-style shims as the finding suggests, that would materially exceed the declared spreadsheet-editing purpose and create a command-execution surface under the guise of benign file processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Even within the visible skill text, the workflow authorizes generic shell execution of Python scripts and LibreOffice/soffice-based recalculation. If the implementation permits arbitrary soffice commands or uses gcc/LD_PRELOAD-style shims as the finding suggests, that would materially exceed the declared spreadsheet-editing purpose and create a command-execution surface under the guise of benign file processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Even within the visible skill text, the workflow authorizes generic shell execution of Python scripts and LibreOffice/soffice-based recalculation. If the implementation permits arbitrary soffice commands or uses gcc/LD_PRELOAD-style shims as the finding suggests, that would materially exceed the declared spreadsheet-editing purpose and create a command-execution surface under the guise of benign file processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Even within the visible skill text, the workflow authorizes generic shell execution of Python scripts and LibreOffice/soffice-based recalculation. If the implementation permits arbitrary soffice commands or uses gcc/LD_PRELOAD-style shims as the finding suggests, that would materially exceed the declared spreadsheet-editing purpose and create a command-execution surface under the guise of benign file processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Even within the visible skill text, the workflow authorizes generic shell execution of Python scripts and LibreOffice/soffice-based recalculation. If the implementation permits arbitrary soffice commands or uses gcc/LD_PRELOAD-style shims as the finding suggests, that would materially exceed the declared spreadsheet-editing purpose and create a command-execution surface under the guise of benign file processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Even within the visible skill text, the workflow authorizes generic shell execution of Python scripts and LibreOffice/soffice-based recalculation. If the implementation permits arbitrary soffice commands or uses gcc/LD_PRELOAD-style shims as the finding suggests, that would materially exceed the declared spreadsheet-editing purpose and create a command-execution surface under the guise of benign file processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Even within the visible skill text, the workflow authorizes generic shell execution of Python scripts and LibreOffice/soffice-based recalculation. If the implementation permits arbitrary soffice commands or uses gcc/LD_PRELOAD-style shims as the finding suggests, that would materially exceed the declared spreadsheet-editing purpose and create a command-execution surface under the guise of benign file processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Even within the visible skill text, the workflow authorizes generic shell execution of Python scripts and LibreOffice/soffice-based recalculation. If the implementation permits arbitrary soffice commands or uses gcc/LD_PRELOAD-style shims as the finding suggests, that would materially exceed the declared spreadsheet-editing purpose and create a command-execution surface under the guise of benign file processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Even within the visible skill text, the workflow authorizes generic shell execution of Python scripts and LibreOffice/soffice-based recalculation. If the implementation permits arbitrary soffice commands or uses gcc/LD_PRELOAD-style shims as the finding suggests, that would materially exceed the declared spreadsheet-editing purpose and create a command-execution surface under the guise of benign file processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Even within the visible skill text, the workflow authorizes generic shell execution of Python scripts and LibreOffice/soffice-based recalculation. If the implementation permits arbitrary soffice commands or uses gcc/LD_PRELOAD-style shims as the finding suggests, that would materially exceed the declared spreadsheet-editing purpose and create a command-execution surface under the guise of benign file processing.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/office/soffice.py (reported line 56)May include surrounding context.

python
def get_soffice_env() -> dict:
    env = os.environ.copy()
    if platform.system() == "Linux":
        env["SAL_USE_VCLPLUGIN"] = "svp"

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The helper silently prepares and injects an LD_PRELOAD native shim into LibreOffice, which is a powerful code-injection mechanism unrelated to ordinary spreadsheet manipulation from a user's perspective. In a spreadsheet skill context, hidden native-code compilation and preload behavior greatly expands the attack surface and could be abused to execute arbitrary code or mask unsafe behavior under the guise of file conversion.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file implements DOCX-specific validation and repair inside a skill explicitly scoped for spreadsheet deliverables. That scope mismatch expands the skill's effective authority to process and potentially alter Word document contents, increasing the chance of unintended file handling, confused-deputy behavior, or misuse of a spreadsheet workflow to touch unrelated document types.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file implements a Word DOCX redlining validator inside a skill whose manifest is explicitly limited to spreadsheet handling. That scope mismatch is dangerous because out-of-scope document-processing code can introduce hidden capabilities, bypass expected review boundaries, and cause the agent to touch file types users and defenders would not expect this skill to access.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill explicitly instructs use of Python scripts, shell execution, file reads/writes, and environment-dependent tools like LibreOffice, but it declares no tool scope or permissions boundary. That makes the effective capability set broader and less reviewable, increasing the risk of unintended command execution or file modification beyond the user’s expected spreadsheet task.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger language is very broad and explicitly says to activate even on casual mentions like 'the xlsx in my downloads.' Overbroad triggering can cause the agent to invoke a high-capability file-modifying skill in situations where the user did not clearly request spreadsheet manipulation, increasing risk of unnecessary file access or edits.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill discusses creating and modifying spreadsheet files but does not clearly warn the user that it may overwrite, save, or materially alter files on disk. In a file-editing context, lack of up-front modification notice raises the chance of unintended destructive changes or user surprise about persistence.

Content

No source excerpt is available for this finding.

Behavior Manipulation

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Subtle instructions detected that may alter agent decision-making or introduce hidden biases.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

CRITICAL: Use Formulas, Not Hardcoded Values

Always use Excel formulas instead of calculating values in Python and hardcoding them. This ensures the spreadsheet remains dynamic and updateable.

❌ WRONG - Hardcoding Calculated Values

python

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code file performs a direct file write to the input document XML, modifying user data in place. Although the module docstring describes the purpose, there is no confirmation prompt, logging/print statement, or explicit warning at the write site that the original document content will be changed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This packer explicitly supports DOCX and PPTX in addition to XLSX, which exceeds the stated spreadsheet-only scope of the skill. In an agent setting, this broadens the file types and code paths available to the model, increasing the chance of unintended activation, misuse on non-spreadsheet Office documents, and exposure to document-processing behaviors that were not justified or reviewed for this skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The validation and auto-repair logic includes DOCX- and PPTX-specific validators and redlining behavior even though the skill is described as spreadsheet-focused. That mismatch creates unnecessary capabilities for modifying non-spreadsheet Office content, which can enable unintended document transformation paths and increases risk because those extra behaviors are harder to justify, test, and constrain within the skill’s intended trust boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The helper launches soffice via subprocess.run and, in the shim path, also executes gcc. The code lacks print/log disclosure or confirmation at the call sites, so consumers may trigger external command execution without a visible warning from this module itself.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/office/soffice.py (reported line 69)May include surrounding context.

python
def run_soffice(args: list[str], **kwargs) -> subprocess.CompletedProcess:
    env = get_soffice_env()
    return subprocess.run([get_soffice_cmd()] + args, env=env, **kwargs)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Writing C source and a shared library into the temporary directory without explicit disclosure or safeguards is risky because temp locations are commonly shared and targetable. The lack of visibility and secure file-handling practices makes it easier for this helper to be abused or to surprise operators with unexpected native-code creation on disk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.