sensitivity-tables
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell command to recalculate workbooks using a headless instance of LibreOffice (
libreoffice --headless --convert-to xlsx). This involves spawning a system subprocess to process files. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it ingests and processes external data from user-provided Excel workbooks to generate logic and formulas.
- Ingestion points: The skill reads data and structure from a source Excel model and specific cell addresses provided by the user or environment (
SKILL.md). - Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following malicious instructions that might be embedded within the source Excel file's metadata or cell content.
- Capability inventory: The skill utilizes
openpyxlfor file writing,numpyfor data computation, and executes system commands vialibreoffice(SKILL.md). - Sanitization: The instructions do not specify any sanitization, filtering, or validation logic for the content read from the external Excel files before it is used in formula construction or Python execution.
Audit Metadata