Back to skill

Security audit

lhx1

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent spreadsheet helper, but its formula recalculation script makes persistent LibreOffice macro changes and can modify workbooks in place without enough user control.

Review this skill before installing if you work with important spreadsheets. It can read and modify spreadsheet files, and formula recalculation can save changes back to the workbook. More importantly, the bundled script writes a LibreOffice macro into your normal user profile and reuses it later; prefer an isolated LibreOffice profile or a patched version that asks before changing local office configuration and saves recalculated copies instead of originals.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
recalc.py:20
Finding

Persistent LibreOffice Macro Is Reused Without Integrity Validation

Content
View full analysis
Sub RecalculateAndSave() ThisComponent.calculateAll() ThisComponent.store() ThisComponent.close(True) End Sub ''' try: with open(macro_file, 'w') as f: f.write(macro_content) return True except Exception: return False ``` The accepted macro is subsequently executed: ```python cmd = [ 'soffice', '--headless', '--norestore', 'vnd.sun.star.script:Standard.Module1.RecalculateAndSave?language=Basic&location=application', abs_path ] ``` ### Technical Analysis The script installs `Module1.xba` into the user's persistent, application-wide LibreOffice profile rather than an iso ...[truncated 2437 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill claims broad spreadsheet creation, editing, analysis, and visualization support, but the documented privileged behavior includes running a recalculation script and modifying LibreOffice user configuration by installing a macro. This mismatch is dangerous because users may consent to a benign-seeming spreadsheet helper while the skill performs undeclared local-environment changes and shell-driven actions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documentation instructs use of file reads, file writes, and shell execution, including running a local recalculation script, but it declares no explicit tool scope or permission boundaries. In an agent setting, this can cause the skill to be invoked with broader capabilities than users expect and increases the chance of unintended file modification or command execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation text is extremely broad and could match nearly any spreadsheet-related task, increasing the likelihood of automatic invocation in contexts involving sensitive local files. When paired with write and shell-capable workflows, overbroad routing raises the risk of unnecessary access, unintended edits, or execution of higher-risk operations without a clearly bounded use case.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The examples show direct workbook saves and structural edits such as inserting rows, deleting columns, and writing output files without guidance to confirm with the user or preserve backups. In practice, this can lead to destructive changes to user data, especially when operating on existing spreadsheets with formulas, templates, or hidden dependencies.

Content

No source excerpt is available for this finding.

Behavior Manipulation

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Subtle instructions detected that may alter agent decision-making or introduce hidden biases.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

CRITICAL: Use Formulas, Not Hardcoded Values

Always use Excel formulas instead of calculating values in Python and hardcoding them. This ensures the spreadsheet remains dynamic and updateable.

❌ WRONG - Hardcoding Calculated Values

python

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script writes a LibreOffice macro into the user's persistent application macro directory without an explicit opt-in or prominent warning. Modifying a user's office automation environment creates lasting side effects, can override existing configuration, and expands trust in future macro execution in a context that often handles untrusted documents.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · recalc.py (reported line 31)May include surrounding context.

python
return True
    
    if not os.path.exists(macro_dir):
        subprocess.run(['soffice', '--headless', '--terminate_after_init'], 
                      capture_output=True, timeout=10)
        os.makedirs(macro_dir, exist_ok=True)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The embedded macro calls ThisComponent.store(), which saves changes back into the input workbook, but the tool description and flow do not clearly warn at the point of action that the original file will be modified. In a spreadsheet-processing skill, silent in-place modification is risky because users may provide sensitive or important workbooks expecting analysis only, and recalculation may alter formulas, cached values, formatting, or compatibility details.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · recalc.py (reported line 84)May include surrounding context.

python
if platform.system() == 'Darwin':
            # Check if gtimeout is available on macOS
            try:
                subprocess.run(['gtimeout', '--version'], capture_output=True, timeout=1, check=False)
                timeout_cmd = 'gtimeout'
            except (FileNotFoundError, subprocess.TimeoutExpired):
                pass

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · recalc.py (reported line 92)May include surrounding context.

python
if timeout_cmd:
            cmd = [timeout_cmd, str(timeout)] + cmd
    
    result = subprocess.run(cmd, capture_output=True, text=True)
    
    if result.returncode != 0 and result.returncode != 124:  # 124 is timeout exit code
        error_msg = result.stderr or 'Unknown error during recalculation'

Static analysis

No suspicious patterns detected.