The fact that you're already doing Xish stuff in your server makes me wonder if it wouldn't be more sensible to build the whole xbiff functionality into it.
Alternatively can you run the xbiff on a machine which is allowed to see the mail spool directly?