xlsx

Pass

Audited by Gen Agent Trust Hub on Apr 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The recalc.py script invokes the LibreOffice (soffice) binary and the system timeout utility through subprocess.run. This is a functional requirement to enable headless formula recalculation.\n- [COMMAND_EXECUTION]: The script dynamically generates a LibreOffice Basic macro (Module1.xba) and stores it in the user's application configuration directory. This persistence is necessary for the tool to automate spreadsheet recalculation tasks that are not available through CLI flags.\n- [PROMPT_INJECTION]: The skill processes external spreadsheets, which presents a surface for indirect prompt injection. Malicious data in cell values could attempt to influence the agent's logic during error-fixing or analysis steps.\n
  • Ingestion points: Spreadsheet data is processed by openpyxl and pandas within the skill's suggested workflows.\n
  • Boundary markers: No specific delimiters or safety instructions are defined for the data ingestion phase.\n
  • Capability inventory: The skill has the ability to execute subprocess commands (LibreOffice) and write to the local filesystem.\n
  • Sanitization: There is no explicit sanitization of cell content before analysis by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 3, 2026, 07:13 PM
Security Audit — agent-trust-hub — xlsx