spreadsheet-ops
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from spreadsheet files and cloud services (e.g., via
openpyxlandgspread), which represents a potential attack surface for indirect prompt injection. Malicious instructions embedded in cell values or headers could influence agent behavior during processing. This is a characteristic of the skill's intended purpose for read-transform-write pipelines. No specific sanitization or boundary markers are prescribed for the spreadsheet content itself, though standard agent guardrails apply. - [COMMAND_EXECUTION]: The skill includes a local utility script
scripts/verify.shused to validate the syntax of generated Python scripts and the structure of produced Excel files. The script uses standard tools likepy_compileandopenpyxlfor local checks and does not perform network exfiltration, access sensitive system paths, or execute untrusted remote code.
Audit Metadata