skills/andrewhaward2310/.agents/xlsx/Gen Agent Trust Hub

xlsx

Warn

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The recalc.py script performs dynamic code generation by writing a LibreOffice Basic macro (Module1.xba) to the user's local application configuration directory (e.g., ~/.config/libreoffice/ or ~/Library/Application Support/LibreOffice/). This macro is subsequently executed to recalculate workbook formulas.
  • [COMMAND_EXECUTION]: The skill uses the subprocess module to execute the soffice (LibreOffice) binary. While arguments are passed as a list to prevent direct shell injection, this functionality allows the agent to spawn and interact with external system processes.
  • [PROMPT_INJECTION]: The skill contains deceptive metadata; the provided author is 'AndrewHaward2310', yet the LICENSE.txt file and skill headers claim the materials are proprietary to 'Anthropic, PBC'. This inconsistency may mislead users or automated systems regarding the skill's provenance and security profile.
  • [PROMPT_INJECTION]: The skill processes untrusted external data from spreadsheets, creating a surface for indirect prompt injection.
  • Ingestion points: Data is loaded into the agent's context using pandas.read_excel() and openpyxl.load_workbook() in SKILL.md.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore or isolate potentially malicious content within the spreadsheet cells.
  • Capability inventory: The skill is capable of file system writes, configuration modification, and shell command execution via the recalc.py script.
  • Sanitization: There is no evidence of validation or sanitization for spreadsheet formulas or data before they are processed by the calculation engine.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — xlsx