spreadsheet-modeling

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains instructions for the agent to verify the installation of recommended companion skills by executing a shell command on local directories.\n
  • Evidence: ls ~/.claude/skills/ ~/.agent/skills/ ~/.agents/skills/ .claude/skills/ .agent/skills/ .agents/skills/ 2>/dev/null in SKILL.md.\n
  • Context: This is a functional behavior used during initial activation to facilitate dependency management for the AbsolutelySkilled suite.\n- [PROMPT_INJECTION]: The skill operates on spreadsheet data and user requirements, creating an inherent surface for indirect prompt injection.\n
  • Ingestion points: Processes external workbook data, complex formulas, and automation requirements as described in SKILL.md and references/ files.\n
  • Boundary markers: No specific delimiters or "ignore instructions" warnings are defined to isolate untrusted data from processing logic.\n
  • Capability inventory: The skill is designed to generate and facilitate the execution of VBA macros and Google Apps Script automation.\n
  • Sanitization: No explicit sanitization or validation routines for external spreadsheet content are implemented within the instructional logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 01:05 PM
Security Audit — agent-trust-hub — spreadsheet-modeling