xlsx-toolkit
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes .xlsx files provided by the user, which constitutes a potential attack surface for indirect prompt injection. \n
- Ingestion points: The
scripts/xlsx_auditor.pyscript ingests and parses the internal XML structure of Excel workbooks. \n - Boundary markers: The tool extracts structural metrics and named properties, creating a natural boundary between file content and agent instructions. \n
- Capability inventory: Analysis of the provided scripts confirms there are no file-writing, network communication, or shell execution capabilities. \n
- Sanitization: Data is parsed using standard XML libraries to extract specific attributes, without executing cell contents. \n- [SAFE]: No security threats or malicious patterns were detected. The tool follows best practices by using the Python standard library for its operations.
Audit Metadata