excel-handler
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides legitimate functionality for Excel spreadsheet manipulation using trusted libraries like pandas and openpyxl. The code is transparent, well-documented, and adheres to its stated purpose.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external Excel, CSV, and JSON files, which is a standard attack surface for indirect prompt injection. However, the risk is negligible as the skill is limited to local file operations and does not possess capabilities for network access or dynamic code execution.\n
- Ingestion points: The script
scripts/excel_handler.pyingests external data through functions likepd.read_excel,pd.read_csv, andjson.load.\n - Boundary markers: No specific boundary markers or instructions to ignore embedded commands are implemented.\n
- Capability inventory: Restricted to filesystem read and write operations within
scripts/excel_handler.py.\n - Sanitization: Input data is parsed using standard library methods without additional filtering for natural language instruction patterns.
Audit Metadata