xlsx
Pass
Audited by Gen Agent Trust Hub on Apr 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
recalc.pyscript invokes the LibreOffice (soffice) binary and the systemtimeoututility throughsubprocess.run. This is a functional requirement to enable headless formula recalculation.\n- [COMMAND_EXECUTION]: The script dynamically generates a LibreOffice Basic macro (Module1.xba) and stores it in the user's application configuration directory. This persistence is necessary for the tool to automate spreadsheet recalculation tasks that are not available through CLI flags.\n- [PROMPT_INJECTION]: The skill processes external spreadsheets, which presents a surface for indirect prompt injection. Malicious data in cell values could attempt to influence the agent's logic during error-fixing or analysis steps.\n - Ingestion points: Spreadsheet data is processed by
openpyxlandpandaswithin the skill's suggested workflows.\n - Boundary markers: No specific delimiters or safety instructions are defined for the data ingestion phase.\n
- Capability inventory: The skill has the ability to execute subprocess commands (LibreOffice) and write to the local filesystem.\n
- Sanitization: There is no explicit sanitization of cell content before analysis by the agent.
Audit Metadata