xlsx-official
Warn
Audited by Socket on Apr 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Mostly coherent Excel-authoring guidance with no visible credential theft or external data routing. The main concern is the mandatory execution of an unspecified recalc.py script that automatically configures LibreOffice; because that executable path is not included or verifiable from the skill text, the skill carries elevated supply-chain risk despite otherwise benign purpose alignment.
Confidence: 87%Severity: 72%
Audit Metadata