skills/ethan-rio/skills/xlsx/Gen Agent Trust Hub

xlsx

Warn

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Several scripts invoke external tools using subprocess.run to perform system tasks. scripts/office/soffice.py calls gcc to compile internal socket shims. scripts/recalc.py executes soffice (LibreOffice) and utility commands like timeout or gtimeout. scripts/office/validators/redlining.py uses git diff for word-level text comparisons.
  • [DYNAMIC_EXECUTION]: The skill generates and compiles executable code at runtime to facilitate environment compatibility. scripts/office/soffice.py contains an embedded C source string that is written to disk and compiled into a shared library using gcc. scripts/recalc.py dynamically creates a LibreOffice Basic macro file (Module1.xba) and configures the environment to load it.
  • [PRIVILEGE_ESCALATION]: The skill uses advanced techniques to modify process behavior and bypass system-level sandbox constraints. scripts/office/soffice.py utilizes LD_PRELOAD to inject its compiled C shim into the LibreOffice process, overriding standard library functions like socket and listen. This allows it to redirect AF_UNIX socket operations in environments where they are restricted.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external files while maintaining high-capability system access, creating an injection risk surface. Ingestion points: Reads and parses user-supplied Office documents in scripts/recalc.py and validator modules. Boundary markers: Absent. No delimiters or instructions are used to separate user data from agent instructions. Capability inventory: Significant capabilities including subprocess.run, runtime C compilation, and LD_PRELOAD injection. Sanitization: Uses defusedxml to mitigate XML-based attacks but does not perform sanitization on semantic content against prompt injection attempts.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 10, 2026, 10:55 AM
Security Audit — agent-trust-hub — xlsx