skills/lucas-ataides/skills/xlsx/Gen Agent Trust Hub

xlsx

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a robust design pattern that separates data specification from execution. The AI agent generates a structured JSON spec, which is then processed by a fixed, local script. This prevents the agent from generating or executing arbitrary styling code.
  • [COMMAND_EXECUTION]: The skill uses a local Python script scripts/render.py to perform the workbook rendering. This execution is scoped to the skill's primary purpose and handles data safely through standard JSON parsing.
  • [EXTERNAL_DOWNLOADS]: The skill relies on openpyxl, a widely-used and well-known Python library for Excel file manipulation. The script provides clear instructions for its installation via standard package managers.
  • [DATA_EXPOSURE]: The skill focuses on generating new artifacts rather than accessing sensitive system files or environment variables. No exfiltration patterns or unauthorized network operations were found.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes user-supplied data to populate the spreadsheet, the risk of indirect injection is mitigated by the structured rendering process and specific verification steps that check for data consistency rather than executing content from the generated file.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 07:14 PM
Security Audit — agent-trust-hub — xlsx