xlsx
Warn
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
recalc.pyscript performs dynamic code generation by writing a LibreOffice Basic macro (Module1.xba) to the user's local application configuration directory (e.g.,~/.config/libreoffice/or~/Library/Application Support/LibreOffice/). This macro is subsequently executed to recalculate workbook formulas. - [COMMAND_EXECUTION]: The skill uses the
subprocessmodule to execute thesoffice(LibreOffice) binary. While arguments are passed as a list to prevent direct shell injection, this functionality allows the agent to spawn and interact with external system processes. - [PROMPT_INJECTION]: The skill contains deceptive metadata; the provided author is 'AndrewHaward2310', yet the
LICENSE.txtfile and skill headers claim the materials are proprietary to 'Anthropic, PBC'. This inconsistency may mislead users or automated systems regarding the skill's provenance and security profile. - [PROMPT_INJECTION]: The skill processes untrusted external data from spreadsheets, creating a surface for indirect prompt injection.
- Ingestion points: Data is loaded into the agent's context using
pandas.read_excel()andopenpyxl.load_workbook()inSKILL.md. - Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore or isolate potentially malicious content within the spreadsheet cells.
- Capability inventory: The skill is capable of file system writes, configuration modification, and shell command execution via the
recalc.pyscript. - Sanitization: There is no evidence of validation or sanitization for spreadsheet formulas or data before they are processed by the calculation engine.
Audit Metadata