xlsx
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
recalc.pyscript executes thesoffice(LibreOffice) binary viasubprocess.runto perform headless spreadsheet recalculations. The execution is handled through a list of arguments, mitigating basic command injection, and targets a well-known local utility. - [PERSISTENCE]: The skill establishes a persistent configuration by writing a StarBasic macro to the user's local LibreOffice directory. This is used to automate the recalculation process across sessions. Evidence: The
setup_libreoffice_macrofunction inrecalc.pycreates the necessary directory structure and writesModule1.xbato the standard LibreOffice configuration path. - [INDIRECT_PROMPT_INJECTION]: The skill acts as a surface for indirect prompt injection as it is designed to read and process untrusted data from external spreadsheet files. \n
- Ingestion points: Content is ingested via
pd.read_excel()andload_workbook()as seen inSKILL.mdandrecalc.py.\n - Boundary markers: While the skill provides guidelines for formatting, it lacks explicit instructions to the agent to disregard instructions embedded within the spreadsheet data itself.\n
- Capability inventory: The agent has access to file-writing capabilities and the
recalc.pyscript for command execution.\n - Sanitization: No explicit content validation or sanitization is implemented to check cell values for malicious instructions before processing.
Audit Metadata