skills/letta-ai/skills/spreadsheet/Gen Agent Trust Hub

spreadsheet

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill documentation explicitly instructs the agent or user to use sudo apt-get for installing system dependencies like libreoffice and poppler-utils, which involves acquiring administrative privileges.\n- [COMMAND_EXECUTION]: The workflow involves executing shell commands such as soffice for PDF conversion and pdftoppm for rendering sheets, which can be risky if inputs are not strictly controlled.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from spreadsheet files (.xlsx, .csv, .tsv), making it susceptible to embedded malicious instructions.\n
  • Ingestion points: Spreadsheet files loaded via openpyxl and pandas as described in SKILL.md and demonstrated in example scripts.\n
  • Boundary markers: There are no specific markers or instructions provided to the agent to treat cell content strictly as data or to ignore potential embedded instructions.\n
  • Capability inventory: The skill has the ability to write to the local filesystem (using wb.save) and execute external system binaries (soffice, pdftoppm).\n
  • Sanitization: No sanitization, validation, or filtering of spreadsheet content is implemented before processing, recalculating, or rendering.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 07:46 PM
Security Audit — agent-trust-hub — spreadsheet