spreadsheet
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill documentation explicitly instructs the agent or user to use
sudo apt-getfor installing system dependencies likelibreofficeandpoppler-utils, which involves acquiring administrative privileges.\n- [COMMAND_EXECUTION]: The workflow involves executing shell commands such assofficefor PDF conversion andpdftoppmfor rendering sheets, which can be risky if inputs are not strictly controlled.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from spreadsheet files (.xlsx,.csv,.tsv), making it susceptible to embedded malicious instructions.\n - Ingestion points: Spreadsheet files loaded via
openpyxlandpandasas described inSKILL.mdand demonstrated in example scripts.\n - Boundary markers: There are no specific markers or instructions provided to the agent to treat cell content strictly as data or to ignore potential embedded instructions.\n
- Capability inventory: The skill has the ability to write to the local filesystem (using
wb.save) and execute external system binaries (soffice,pdftoppm).\n - Sanitization: No sanitization, validation, or filtering of spreadsheet content is implemented before processing, recalculating, or rendering.
Audit Metadata