xlsx
Warn
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/office/soffice.pydynamically generates C source code at runtime, compiles it into a shared object usinggcc, and then injects it into the LibreOffice process (soffice) using theLD_PRELOADenvironment variable. This technique is used to shim network socket operations. - [DYNAMIC_EXECUTION]: The
recalc.pyscript automatically configures a StarBasic macro (RecalculateAndSave) in the user's LibreOffice configuration directory to enable formula recalculation. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted Excel files, which constitutes a vulnerability surface for indirect prompt injection.
- Ingestion points: Spreadsheets are loaded into the agent context via
pandas.read_excelandopenpyxl.load_workbook(as described inSKILL.mdexamples). - Boundary markers: The provided scripts do not implement explicit delimiters or warnings to ignore instructions embedded within the spreadsheet data.
- Capability inventory: The skill possesses capabilities to write files and execute system commands through the
recalc.pyscript and LibreOffice. - Sanitization: There is no evidence of content filtering or sanitization performed on the spreadsheet data before it is processed by the AI agent.
- [COMMAND_EXECUTION]: Several components of the skill, including
recalc.py,scripts/office/soffice.py, andscripts/office/validators/redlining.py, execute external binaries such assoffice,gcc, andgitvia thesubprocessmodule.
Audit Metadata