Back to skill

Security audit

xlsx

Security checks for vulnerabilities and agentic risk

Overview

This spreadsheet skill is mostly purpose-aligned, but it ships risky LibreOffice process shimming and under-disclosed Word/PowerPoint document tooling that should be reviewed before installing.

Install only if you are comfortable with the skill running local LibreOffice, adding a persistent recalculation macro to the LibreOffice profile, and using a native LD_PRELOAD workaround in restricted environments. For safer use, run it in an isolated workspace/profile and remove or split the DOCX/PPTX helpers if you only intend to approve spreadsheet handling.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/office/soffice.py:24
Finding

Untrusted Shared Temporary Library Loaded Through LD_PRELOAD

Content
View full analysis
dict: env = os.environ.copy() env["SAL_USE_VCLPLUGIN"] = "svp" if _needs_shim(): shim = _ensure_shim() env["LD_PRELOAD"] = str(shim) return env def run_soffice(args: list[str], **kwargs) -> subprocess.CompletedProcess: env = get_soffice_env() return subprocess.run(["soffice"] + args, env=env, **kwargs) _SHIM_SO = Path(tempfile.gettempdir()) / "lo_socket_shim.so" def _needs_shim() -> bool: try: s = socket.socket(socket.AF_UNIX, socket.SOCK_STREAM) s.close() return False except OSError: return True def _ensure_shim() -> Path: if _SHIM_SO.exists(): return _SHIM_SO src = Path(tempfile.gettempdir()) / "lo_socket_shim.c" src.write_text(_SHIM_SOURCE) subprocess.run( ["gcc", "-shared", "-fPIC", "-o", str(_SHIM_SO), str(src), "-ldl"], check=True, capture_output=True, ) src.unlink() return _SHIM_SO ``` ### Technical Analysis The application stores its preload library at the fixed shared-temporary path `/tmp/lo_socket_shim.so`. When the file already exists, `_ensure_shim()` returns it without verifying: - File ownership - File permissions - Whether it is a symbolic link - Whether it is a regular file - Its content or cryptographic digest - Whether it was produced by the current process When Unix-domain sockets are unavailable, the returned path is assigned to `LD_PRELOAD`. LibreOffice is then executed with that environment, causing the operating-system dynamic loader to load the referenced library before starting the application. The predictable source path `/tmp/lo_socket_shim.c` and non-atomic compilation output introduce additional symbolic-link and time-of-c ...[truncated 1544 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/office/validators/base.py:756
Finding

Attacker-Controlled Office XML Parsed Without Explicit Entity Hardening

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (65)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding is partially valid even without the unseen code: the skill is described as a general spreadsheet creation/editing/conversion tool, yet a substantial portion of the actual instructions centers on running a recalculation script that returns JSON diagnostics and may modify local LibreOffice configuration. That narrower and more invasive behavior should be disclosed because it affects user environment and output expectations beyond simply producing a spreadsheet file.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding is partially valid even without the unseen code: the skill is described as a general spreadsheet creation/editing/conversion tool, yet a substantial portion of the actual instructions centers on running a recalculation script that returns JSON diagnostics and may modify local LibreOffice configuration. That narrower and more invasive behavior should be disclosed because it affects user environment and output expectations beyond simply producing a spreadsheet file.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding is partially valid even without the unseen code: the skill is described as a general spreadsheet creation/editing/conversion tool, yet a substantial portion of the actual instructions centers on running a recalculation script that returns JSON diagnostics and may modify local LibreOffice configuration. That narrower and more invasive behavior should be disclosed because it affects user environment and output expectations beyond simply producing a spreadsheet file.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding is partially valid even without the unseen code: the skill is described as a general spreadsheet creation/editing/conversion tool, yet a substantial portion of the actual instructions centers on running a recalculation script that returns JSON diagnostics and may modify local LibreOffice configuration. That narrower and more invasive behavior should be disclosed because it affects user environment and output expectations beyond simply producing a spreadsheet file.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding is partially valid even without the unseen code: the skill is described as a general spreadsheet creation/editing/conversion tool, yet a substantial portion of the actual instructions centers on running a recalculation script that returns JSON diagnostics and may modify local LibreOffice configuration. That narrower and more invasive behavior should be disclosed because it affects user environment and output expectations beyond simply producing a spreadsheet file.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding is partially valid even without the unseen code: the skill is described as a general spreadsheet creation/editing/conversion tool, yet a substantial portion of the actual instructions centers on running a recalculation script that returns JSON diagnostics and may modify local LibreOffice configuration. That narrower and more invasive behavior should be disclosed because it affects user environment and output expectations beyond simply producing a spreadsheet file.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding is partially valid even without the unseen code: the skill is described as a general spreadsheet creation/editing/conversion tool, yet a substantial portion of the actual instructions centers on running a recalculation script that returns JSON diagnostics and may modify local LibreOffice configuration. That narrower and more invasive behavior should be disclosed because it affects user environment and output expectations beyond simply producing a spreadsheet file.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding is partially valid even without the unseen code: the skill is described as a general spreadsheet creation/editing/conversion tool, yet a substantial portion of the actual instructions centers on running a recalculation script that returns JSON diagnostics and may modify local LibreOffice configuration. That narrower and more invasive behavior should be disclosed because it affects user environment and output expectations beyond simply producing a spreadsheet file.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding is partially valid even without the unseen code: the skill is described as a general spreadsheet creation/editing/conversion tool, yet a substantial portion of the actual instructions centers on running a recalculation script that returns JSON diagnostics and may modify local LibreOffice configuration. That narrower and more invasive behavior should be disclosed because it affects user environment and output expectations beyond simply producing a spreadsheet file.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding is partially valid even without the unseen code: the skill is described as a general spreadsheet creation/editing/conversion tool, yet a substantial portion of the actual instructions centers on running a recalculation script that returns JSON diagnostics and may modify local LibreOffice configuration. That narrower and more invasive behavior should be disclosed because it affects user environment and output expectations beyond simply producing a spreadsheet file.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding is partially valid even without the unseen code: the skill is described as a general spreadsheet creation/editing/conversion tool, yet a substantial portion of the actual instructions centers on running a recalculation script that returns JSON diagnostics and may modify local LibreOffice configuration. That narrower and more invasive behavior should be disclosed because it affects user environment and output expectations beyond simply producing a spreadsheet file.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding is partially valid even without the unseen code: the skill is described as a general spreadsheet creation/editing/conversion tool, yet a substantial portion of the actual instructions centers on running a recalculation script that returns JSON diagnostics and may modify local LibreOffice configuration. That narrower and more invasive behavior should be disclosed because it affects user environment and output expectations beyond simply producing a spreadsheet file.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/office/schemas/ecma/fouth-edition/opc-contentTypes.xsd (reported line 1)May include surrounding context.

text
<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<xsd:schema xmlns="http://schemas.openxmlformats.org/package/2006/relationships"
  xmlns:xsd="http://www.w3.org/2001/XMLSchema"
  targetNamespace="http://schemas.openxmlformats.org/package/2006/relationships"

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/office/schemas/ecma/fouth-edition/opc-coreProperties.xsd (reported line 1)May include surrounding context.

text
<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<xsd:schema xmlns="http://schemas.openxmlformats.org/package/2006/relationships"
  xmlns:xsd="http://www.w3.org/2001/XMLSchema"
  targetNamespace="http://schemas.openxmlformats.org/package/2006/relationships"

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/office/schemas/ecma/fouth-edition/opc-relationships.xsd (reported line 1)May include surrounding context.

text
<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<xsd:schema xmlns="http://schemas.openxmlformats.org/package/2006/relationships"
  xmlns:xsd="http://www.w3.org/2001/XMLSchema"
  targetNamespace="http://schemas.openxmlformats.org/package/2006/relationships"

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This helper dynamically creates and injects an LD_PRELOAD shim into a child process, allowing interception of libc calls inside LibreOffice. That is a highly privileged technique unrelated to normal spreadsheet manipulation and significantly more dangerous in this skill context because it introduces arbitrary native-code execution and process-manipulation capability.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/office/soffice.py (reported line 25)May include surrounding context.

python
def get_soffice_env() -> dict:
    env = os.environ.copy()
    env["SAL_USE_VCLPLUGIN"] = "svp"

    if _needs_shim():

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Building arbitrary native code at runtime exceeds the operational needs of a spreadsheet file skill and creates a pathway for execution of tampered code. Because the source and output are placed in the temp directory and the compiler is launched dynamically, an attacker with local influence over the environment or filesystem may be able to interfere with what gets built or executed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file is implemented and documented as a general Office unpacker, explicitly supporting DOCX and PPTX in addition to XLSX, which exceeds the skill's declared spreadsheet-only scope. In an agent setting, this capability expansion can cause the wrong skill to be invoked on non-spreadsheet documents, broadening access to document content and edits beyond the user-approved domain.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The runtime validation explicitly permits .docx and .pptx files, directly contradicting the skill metadata that says this skill is for spreadsheet inputs/outputs. This mismatch weakens policy boundaries: an attacker or confused workflow could route non-spreadsheet Office documents through a spreadsheet skill, enabling unintended document extraction and transformation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The DOCX-specific tracked-change simplification and run-merging logic introduces capabilities unrelated to spreadsheet processing, showing the skill can modify word-processing documents in semantically significant ways. In the context of a spreadsheet-only skill, this increases danger because it enables silent alteration of document review history or formatting outside the authorized scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script’s stated and implemented scope includes .docx and .pptx processing, which exceeds the xlsx skill’s spreadsheet-only manifest. This creates a scope-drift vulnerability: an agent invoking this skill could be induced to operate on Word or PowerPoint files under a spreadsheet-labeled capability, bypassing user and policy expectations about what the skill is allowed to handle.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code explicitly accepts .docx and .pptx files and instantiates DOCX/PPTX validators, directly contradicting the spreadsheet-focused skill definition. In agent systems, this mismatch is dangerous because capability routing and approval decisions often rely on the manifest; hidden broader file handling can cause unauthorized processing of non-spreadsheet content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill manifest scopes this skill to spreadsheet inputs/outputs, but this file implements Word DOCX validation and repair logic. That scope mismatch is dangerous because an agent may invoke code capable of opening and modifying non-spreadsheet Office archives, expanding the skill’s effective authority beyond what users and reviewers expect and enabling unintended document tampering.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest says this skill should be used for spreadsheet files such as .xlsx, .xlsm, .csv, and .tsv, with spreadsheet files as the primary input/output. This file instead implements validation logic for PowerPoint PresentationML/PPTX content, including slide masters, slide layouts, and notes slides, which is outside spreadsheet processing and indicates the skill actually contains non-spreadsheet document handling behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.