The missing reliability layer for spreadsheet work in LLM agents. Read, write, diff, validate, and analyze .xlsx files end-to-end — with merged cells, formulas, named ranges, conditional formatting, pivots, and charts preserved.
LPM treats this as warn-only first-party agent extension lifecycle risk. Global installation automatically configures the package's own Claude Code MCP extension. This establishes a first-party extension lifecycle risk, without confirmed malicious control hijacking.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
lib/installer-cleanup.jsView on unpkg · L27Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
lib/mcp-register.jsView on unpkg · L4Package source invokes a package manager install command at runtime.
lib/auto-upgrade.jsView on unpkg · L14Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/auto-upgrade.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/auto-upgrade.jsView on unpkgPackage ships high-entropy non-source blobs.
samples/reporting-pack-v2.xlsxView on unpkgPackage ships compressed or archive-like blobs.
samples/reporting-pack-v2.xlsxView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
samples/reporting-pack-v2.xlsxView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
mcp.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/discover.jsView on unpkgThis report applies to xlsx-for-ai@4.0.10.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
lib/installer-cleanup.jsView on unpkg · L27Package ships high-entropy non-source blobs.
samples/reporting-pack-v2.xlsxView on unpkgPackage ships compressed or archive-like blobs.
samples/reporting-pack-v2.xlsxView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
samples/reporting-pack-v2.xlsxView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
mcp.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/discover.jsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
lib/mcp-register.jsView on unpkg · L4Package source invokes a package manager install command at runtime.
lib/auto-upgrade.jsView on unpkg · L14Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/auto-upgrade.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/auto-upgrade.jsView on unpkg