xlsx

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The recalc.py script utilizes subprocess.run to invoke system utilities including LibreOffice (soffice) and the gtimeout command. All commands are constructed using argument lists rather than shell strings, which is a secure practice that prevents shell injection vulnerabilities.
  • [DYNAMIC_EXECUTION]: The recalc.py script dynamically generates a StarBasic macro file (Module1.xba) within the user's LibreOffice configuration directory. This macro is required to trigger formula recalculation through the headless command-line interface. The code written to the file is based on a fixed, static template provided within the script.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted spreadsheet files, which represents an attack surface for indirect prompt injection.
  • Ingestion points: External data enters the agent context via pd.read_excel and openpyxl.load_workbook as documented in SKILL.md and recalc.py.
  • Boundary markers: The instructions do not define specific delimiters or "ignore" directives for data processed from spreadsheet cells.
  • Capability inventory: The skill possesses capabilities for filesystem writes, sub-process execution of productivity software, and modification of application configuration files.
  • Sanitization: There is no evidence of sanitization or validation logic for the content of spreadsheet cells or the structure of formula strings before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:20 AM
Security Audit — agent-trust-hub — xlsx