travel-plan-spreadsheet-generator
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data, such as travel notes, PDF bookings, and screenshots. While this presents an attack surface where malicious instructions could be embedded in the source data, the skill includes explicit instructions and design patterns to mitigate accidental obedience.
- Ingestion points: Identified in
SKILL.mdand processed via the--trip-modelargument inscripts/build_workbook.py. - Boundary markers: The skill uses an intake protocol (
references/intake-protocol.md) and research policy (references/research-policy.md) that requires surfacing contradictions as review flags rather than executing them. - Capability inventory: The skill primarily writes Excel files using
openpyxl. It includes a testing script (scripts/test_skill.py) that executes local scripts viasubprocess. - Sanitization: Filenames are sanitized using regex in the
safe_filename_partfunction withinscripts/build_workbook.py. - [COMMAND_EXECUTION]: The
scripts/test_skill.pyutility usessubprocess.run()to perform smoke tests, including checking for dependencies and executing other internal scripts (build_workbook.py,validate_workbook.py, etc.). This is a standard development practice for automated testing of the skill's functionality. - [EXTERNAL_DOWNLOADS]: The testing script
scripts/test_skill.pyattempts to install the well-knownopenpyxllibrary usingpipinside a temporary virtual environment if it is not already available. This is a common and safe practice for ensuring test environments are correctly configured.
Audit Metadata