exceljs
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the 'exceljs' package via the official npm registry. This is a standard and well-known library for Excel manipulation in the Node.js ecosystem.
- [INDIRECT_PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection by reading data from external XLSX files into the agent's context using functions like
readExcel. - Ingestion points: Content is read from external paths via
workbook.xlsx.readFile(filePath)inSKILL.md. - Boundary markers: None identified in the provided examples; data is read and pushed into an array without delimiters.
- Capability inventory: The skill includes file system read (
readFile) and write (writeFile,WorkbookWriter) capabilities. - Sanitization: No sanitization or validation of the ingested Excel cell content is shown in the usage examples.
Audit Metadata