xlsx
Audited by Socket on Mar 6, 2026
1 alert found:
Obfuscated FileThe reviewed documentation and examples are functionally benign and align with legitimate spreadsheet automation and financial-modeling use. There is no direct evidence in the provided fragment of malware, obfuscation, hardcoded credentials, or network exfiltration. However, two supply-chain and operational risks merit attention before executing on sensitive hosts: (1) the recalc.py utility's unspecified 'automatic LibreOffice configuration' — review its implementation for installers, network calls, or elevated actions; and (2) the recommended 'scientific-schematics' skill and associated scripts — verify provenance, source code, and network behavior. Treat referenced helper scripts as untrusted until audited. Overall: acceptable to use after auditing recalc.py and any transitive skills; avoid running automated configuration steps on high-value systems without review.