Back to skill

Security audit

Minimax Xlsx

Security checks for vulnerabilities and agentic risk

Overview

This spreadsheet skill is mostly aligned with making Excel workbooks, but its recalculation helper persistently changes the user's LibreOffice macro profile and may overwrite existing macros.

Install only if you are comfortable with a spreadsheet skill that runs local commands and modifies your LibreOffice user macro profile. Prefer running it in a contained workspace or with an isolated LibreOffice profile, and avoid using it on sensitive or untrusted spreadsheets until the persistent macro behavior and missing CLI provenance are addressed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/recalc.py:19
Finding

Persistent Modification and Potential Overwrite of the User-Wide LibreOffice Macro Profile

Content
View full analysis
Sub RecalculateAndSave() ThisComponent.calculateAll() ThisComponent.store() ThisComponent.close(True) End Sub """ try: with open(macro_file, "w") as f: f.write(macro_content) return True except Exception: return False ``` ### Technical Analysis The recalculation helper installs a macro into LibreOffice's global per-user `Standard` macro library. This location is shared by unrelated LibreOffice documents and sessions and persists after the Skill finishes. The Skill only needs to recalculate a specific workbook. Permanently changing the user's application profile is therefore broader than the minimum access required for that function. T ...[truncated 1872 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/recalc.py:75
Finding

Recalculation Timeout Is Treated as a Non-Fatal Result

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The activation language is extremely broad, covering essentially any task involving tabular data, numeric analysis, or spreadsheet generation. In combination with the skill's shell and file-manipulation workflow, this increases the chance of over-invocation on tasks that do not need such powerful capabilities, expanding exposure to unnecessary code execution, file handling, and unintended processing of sensitive data.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill instructs use of file read/write and shell-capable tooling, including execution of local Python scripts, LibreOffice headless recalculation, and a native CLI binary, but it does not declare any explicit tool scope restrictions. That creates an unnecessary trust gap: once activated for a broad class of tasks, the agent may gain powerful filesystem and command-execution capabilities without an allowlisted boundary, increasing the risk of command misuse, unsafe file access, or abuse of helper binaries.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script writes a macro file into the user's persistent LibreOffice profile under Standard/Module1.xba, modifying application state outside the target workbook. This creates cross-task side effects and a persistence mechanism: later LibreOffice sessions or other workflows may inherit or invoke the installed macro, which is especially risky in an agent skill that processes untrusted spreadsheets on shared systems.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script installs and executes an application-level LibreOffice macro as part of opening spreadsheets, expanding trust from a single file to the entire office runtime. In the context of a spreadsheet-processing skill, this is more dangerous because it handles adversarial documents and automates office software, increasing the blast radius of macro abuse, profile poisoning, or unintended macro interactions across runs.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/recalc.py (reported line 31)May include surrounding context.

python
return True

    if not os.path.exists(macro_dir):
        subprocess.run(["soffice", "--headless", "--terminate_after_init"], capture_output=True, timeout=10)
        os.makedirs(macro_dir, exist_ok=True)

    macro_content = """<?xml version="1.0" encoding="UTF-8"?>

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/recalc.py (reported line 85)May include surrounding context.

python
if platform.system() == "Darwin":
            # Check if gtimeout is available on macOS
            try:
                subprocess.run(["gtimeout", "--version"], capture_output=True, timeout=1, check=False)
                timeout_cmd = "gtimeout"
            except (FileNotFoundError, subprocess.TimeoutExpired):
                pass

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/recalc.py (reported line 92)May include surrounding context.

python
if timeout_cmd:
            cmd = [timeout_cmd, str(timeout)] + cmd

    result = subprocess.run(cmd, capture_output=True, text=True)

    if result.returncode != 0 and result.returncode != 124:  # 124 is timeout exit code
        error_msg = result.stderr or "Unknown error during recalculation"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L064 instructs the skill to use different gain/loss colors based on market locale, including a mandatory mainland China convention described as "non-negotiable." This imposes a locale-specific behavior in natural language without offering user choice or indicating that the behavior is optional or user-configurable.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.