xlsx

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The recalc.py script uses subprocess.run and subprocess.Popen to invoke system binaries including soffice (LibreOffice), Xvfb, pgrep, and timeout utilities to manage headless spreadsheet recalculation.
  • [PERSISTENCE]: The recalc.py script creates a persistent StarBasic macro file (Module1.xba) in the user's LibreOffice configuration directory (e.g., ~/Library/Application Support/LibreOffice/4/user/basic/Standard). This persistent modification to the application environment is used to enable automated formula recalculation.
  • [DYNAMIC_EXECUTION]: The skill generates and writes a hardcoded StarBasic macro to the filesystem, which is subsequently executed by LibreOffice using a vnd.sun.star.script URI to trigger the formula recalculation process.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external .xlsx and .csv files, representing a surface for indirect prompt injection. Ingestion points: recalc.py, pandas.read_excel, and openpyxl.load_workbook. Boundary markers: Not explicitly defined in documentation for cell content processing. Capability inventory: Subprocess execution of soffice and file-write access to config directories. Sanitization: The tool validates for formula errors (e.g., #REF!) but does not sanitize cell contents for natural language instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:10 AM
Security Audit — agent-trust-hub — xlsx