skills/4444j99/a-i--skills/xlsx/Gen Agent Trust Hub

xlsx

Warn

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The script scripts/office/soffice.py dynamically generates C source code at runtime, compiles it into a shared object using gcc, and then injects it into the LibreOffice process (soffice) using the LD_PRELOAD environment variable. This technique is used to shim network socket operations.
  • [DYNAMIC_EXECUTION]: The recalc.py script automatically configures a StarBasic macro (RecalculateAndSave) in the user's LibreOffice configuration directory to enable formula recalculation.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted Excel files, which constitutes a vulnerability surface for indirect prompt injection.
  • Ingestion points: Spreadsheets are loaded into the agent context via pandas.read_excel and openpyxl.load_workbook (as described in SKILL.md examples).
  • Boundary markers: The provided scripts do not implement explicit delimiters or warnings to ignore instructions embedded within the spreadsheet data.
  • Capability inventory: The skill possesses capabilities to write files and execute system commands through the recalc.py script and LibreOffice.
  • Sanitization: There is no evidence of content filtering or sanitization performed on the spreadsheet data before it is processed by the AI agent.
  • [COMMAND_EXECUTION]: Several components of the skill, including recalc.py, scripts/office/soffice.py, and scripts/office/validators/redlining.py, execute external binaries such as soffice, gcc, and git via the subprocess module.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — xlsx