xlsx
Warn
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The script
scripts/office/soffice.pydynamically generates C source code, writes it to a temporary file, and compiles it usinggccinto a shared library. This library is then loaded into thesofficeprocess environment via theLD_PRELOADenvironment variable to hook system calls for socket management. This runtime compilation and injection of code is a significant security concern. - [COMMAND_EXECUTION]: The skill makes extensive use of the
subprocessmodule to execute external binaries. Inscripts/office/soffice.py, it executesgccandsoffice. Inscripts/recalc.py, it executestimeoutorgtimeout. Inscripts/office/validators/redlining.py, it executesgit difffor comparing document versions. - [PROMPT_INJECTION]: The skill ingests and processes untrusted spreadsheet data which creates a vulnerability surface for indirect prompt injection.
- Ingestion points:
scripts/recalc.pyandscripts/office/validate.pyload user-provided files viaopenpyxlandzipfilemodules. - Boundary markers: Absent; there are no clear delimiters or instructions to the agent to disregard content found within the spreadsheet data.
- Capability inventory: The skill possesses powerful capabilities including arbitrary shell command execution and runtime C compilation.
- Sanitization: While
defusedxmlis used for XML parsing, the skill lacks sanitization for spreadsheet cell content that could be used to influence agent behavior.
Audit Metadata