xlsx-toolkit

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes .xlsx files provided by the user, which constitutes a potential attack surface for indirect prompt injection. \n
  • Ingestion points: The scripts/xlsx_auditor.py script ingests and parses the internal XML structure of Excel workbooks. \n
  • Boundary markers: The tool extracts structural metrics and named properties, creating a natural boundary between file content and agent instructions. \n
  • Capability inventory: Analysis of the provided scripts confirms there are no file-writing, network communication, or shell execution capabilities. \n
  • Sanitization: Data is parsed using standard XML libraries to extract specific attributes, without executing cell contents. \n- [SAFE]: No security threats or malicious patterns were detected. The tool follows best practices by using the Python standard library for its operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 11:51 PM
Security Audit — agent-trust-hub — xlsx-toolkit