xlsx
Warn
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Several scripts invoke external tools using
subprocess.runto perform system tasks.scripts/office/soffice.pycallsgccto compile internal socket shims.scripts/recalc.pyexecutessoffice(LibreOffice) and utility commands liketimeoutorgtimeout.scripts/office/validators/redlining.pyusesgit difffor word-level text comparisons. - [DYNAMIC_EXECUTION]: The skill generates and compiles executable code at runtime to facilitate environment compatibility.
scripts/office/soffice.pycontains an embedded C source string that is written to disk and compiled into a shared library usinggcc.scripts/recalc.pydynamically creates a LibreOffice Basic macro file (Module1.xba) and configures the environment to load it. - [PRIVILEGE_ESCALATION]: The skill uses advanced techniques to modify process behavior and bypass system-level sandbox constraints.
scripts/office/soffice.pyutilizesLD_PRELOADto inject its compiled C shim into the LibreOffice process, overriding standard library functions likesocketandlisten. This allows it to redirect AF_UNIX socket operations in environments where they are restricted. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external files while maintaining high-capability system access, creating an injection risk surface. Ingestion points: Reads and parses user-supplied Office documents in
scripts/recalc.pyand validator modules. Boundary markers: Absent. No delimiters or instructions are used to separate user data from agent instructions. Capability inventory: Significant capabilities includingsubprocess.run, runtime C compilation, andLD_PRELOADinjection. Sanitization: Usesdefusedxmlto mitigate XML-based attacks but does not perform sanitization on semantic content against prompt injection attempts.
Audit Metadata