travel-plan-spreadsheet-generator

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data, such as travel notes, PDF bookings, and screenshots. While this presents an attack surface where malicious instructions could be embedded in the source data, the skill includes explicit instructions and design patterns to mitigate accidental obedience.
  • Ingestion points: Identified in SKILL.md and processed via the --trip-model argument in scripts/build_workbook.py.
  • Boundary markers: The skill uses an intake protocol (references/intake-protocol.md) and research policy (references/research-policy.md) that requires surfacing contradictions as review flags rather than executing them.
  • Capability inventory: The skill primarily writes Excel files using openpyxl. It includes a testing script (scripts/test_skill.py) that executes local scripts via subprocess.
  • Sanitization: Filenames are sanitized using regex in the safe_filename_part function within scripts/build_workbook.py.
  • [COMMAND_EXECUTION]: The scripts/test_skill.py utility uses subprocess.run() to perform smoke tests, including checking for dependencies and executing other internal scripts (build_workbook.py, validate_workbook.py, etc.). This is a standard development practice for automated testing of the skill's functionality.
  • [EXTERNAL_DOWNLOADS]: The testing script scripts/test_skill.py attempts to install the well-known openpyxl library using pip inside a temporary virtual environment if it is not already available. This is a common and safe practice for ensuring test environments are correctly configured.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:13 AM
Security Audit — agent-trust-hub — travel-plan-spreadsheet-generator