xlsx

Fail

Audited by Socket on Mar 6, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The reviewed documentation and examples are functionally benign and align with legitimate spreadsheet automation and financial-modeling use. There is no direct evidence in the provided fragment of malware, obfuscation, hardcoded credentials, or network exfiltration. However, two supply-chain and operational risks merit attention before executing on sensitive hosts: (1) the recalc.py utility's unspecified 'automatic LibreOffice configuration' — review its implementation for installers, network calls, or elevated actions; and (2) the recommended 'scientific-schematics' skill and associated scripts — verify provenance, source code, and network behavior. Treat referenced helper scripts as untrusted until audited. Overall: acceptable to use after auditing recalc.py and any transitive skills; avoid running automated configuration steps on high-value systems without review.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 6, 2026, 01:25 AM
Package URL
pkg:socket/skills-sh/K-Dense-AI%2Fclaude-scientific-skills%2Fxlsx%2F@f5fb1cdb7993b2feee8367e983e9d4d58d2eedd4