The missing reliability layer for spreadsheet work in LLM agents. Read, write, diff, validate, and analyze .xlsx files end-to-end — with merged cells, formulas, named ranges, conditional formatting, pivots, and charts preserved.
LPM treats this as warn-only first-party agent extension lifecycle risk. A global install automatically adds this package's MCP command to the user's Claude Code configuration. When that MCP server starts, it can fetch a remote catalog and automatically reinstall the package from the registry.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
lib/installer-cleanup.jsView on unpkg · L27Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
lib/mcp-register.jsView on unpkg · L4Package source invokes a package manager install command at runtime.
lib/auto-upgrade.jsView on unpkg · L14Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/auto-upgrade.jsView on unpkgPackage ships high-entropy non-source blobs.
samples/reporting-pack-v2.xlsxView on unpkgPackage ships compressed or archive-like blobs.
samples/reporting-pack-v2.xlsxView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
samples/reporting-pack-v2.xlsxView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
mcp.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
lib/discover.jsView on unpkgThis report applies to xlsx-for-ai@4.0.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L42Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L42Package ships high-entropy non-source blobs.
samples/reporting-pack-v2.xlsxView on unpkgPackage ships compressed or archive-like blobs.
samples/reporting-pack-v2.xlsxView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
samples/reporting-pack-v2.xlsxView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
mcp.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
lib/discover.jsView on unpkgPackage source references child process execution.
lib/installer-cleanup.jsView on unpkg · L27Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
lib/mcp-register.jsView on unpkg · L4Package source invokes a package manager install command at runtime.
lib/auto-upgrade.jsView on unpkg · L14Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/auto-upgrade.jsView on unpkg