skills/claudiodearaujo/izacenter/xlsx/Gen Agent Trust Hub

xlsx

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The recalc.py script executes the soffice (LibreOffice) binary via subprocess.run to perform headless spreadsheet recalculations. The execution is handled through a list of arguments, mitigating basic command injection, and targets a well-known local utility.
  • [PERSISTENCE]: The skill establishes a persistent configuration by writing a StarBasic macro to the user's local LibreOffice directory. This is used to automate the recalculation process across sessions. Evidence: The setup_libreoffice_macro function in recalc.py creates the necessary directory structure and writes Module1.xba to the standard LibreOffice configuration path.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a surface for indirect prompt injection as it is designed to read and process untrusted data from external spreadsheet files. \n
  • Ingestion points: Content is ingested via pd.read_excel() and load_workbook() as seen in SKILL.md and recalc.py.\n
  • Boundary markers: While the skill provides guidelines for formatting, it lacks explicit instructions to the agent to disregard instructions embedded within the spreadsheet data itself.\n
  • Capability inventory: The agent has access to file-writing capabilities and the recalc.py script for command execution.\n
  • Sanitization: No explicit content validation or sanitization is implemented to check cell values for malicious instructions before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:32 PM
Security Audit — agent-trust-hub — xlsx