skills/hk-hub/agentskills/xlsx/Gen Agent Trust Hub

xlsx

Warn

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The script scripts/office/soffice.py dynamically generates C source code, writes it to a temporary file, and compiles it using gcc into a shared library. This library is then loaded into the soffice process environment via the LD_PRELOAD environment variable to hook system calls for socket management. This runtime compilation and injection of code is a significant security concern.
  • [COMMAND_EXECUTION]: The skill makes extensive use of the subprocess module to execute external binaries. In scripts/office/soffice.py, it executes gcc and soffice. In scripts/recalc.py, it executes timeout or gtimeout. In scripts/office/validators/redlining.py, it executes git diff for comparing document versions.
  • [PROMPT_INJECTION]: The skill ingests and processes untrusted spreadsheet data which creates a vulnerability surface for indirect prompt injection.
  • Ingestion points: scripts/recalc.py and scripts/office/validate.py load user-provided files via openpyxl and zipfile modules.
  • Boundary markers: Absent; there are no clear delimiters or instructions to the agent to disregard content found within the spreadsheet data.
  • Capability inventory: The skill possesses powerful capabilities including arbitrary shell command execution and runtime C compilation.
  • Sanitization: While defusedxml is used for XML parsing, the skill lacks sanitization for spreadsheet cell content that could be used to influence agent behavior.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 05:31 PM
Security Audit — agent-trust-hub — xlsx