xlsx
Warn
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The recalc.py script executes system commands via subprocess.run to invoke the soffice binary for LibreOffice. This is used to trigger headless formula recalculation. Found in recalc.py at line 91.
- [COMMAND_EXECUTION]: The skill modifies local application configurations by writing a LibreOffice Basic macro file (Module1.xba) to the user's configuration directory. Found in recalc.py at lines 20-51.
- [PROMPT_INJECTION]: The skill processes untrusted Excel files, creating a surface for indirect prompt injection where embedded instructions in spreadsheet cells could influence agent behavior.
- Ingestion points: User-provided spreadsheets loaded via pd.read_excel and load_workbook in SKILL.md.
- Boundary markers: Absent; no specific delimiters or system instructions are provided to ignore embedded data instructions.
- Capability inventory: System command execution (soffice), file system access, and Python code execution.
- Sanitization: Absent; no validation or escaping of cell content is performed before analysis or processing.
Audit Metadata