Calc

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous shell commands for automating LibreOffice Calc, including starting the application in headless mode and performing batch conversions between ODS, XLSX, CSV, and PDF formats using the soffice binary.
  • [EXTERNAL_DOWNLOADS]: Instructions include the installation of standard Python libraries from official registries, specifically ezodf, odfpy, and pandas, to handle spreadsheet manipulation and data analysis.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents an attack surface for indirect prompt injection as it is designed to ingest and process data from external spreadsheet formats (ODS, XLSX, CSV).
  • Ingestion points: Data is loaded into the agent's context through libraries like ezodf and the LibreOffice UNO API (doc.getSheets().getByIndex(0)).
  • Boundary markers: None provided in the sample scripts to differentiate between data and instructions.
  • Capability inventory: The skill has capabilities to write files (doc.save, doc.storeToURL) and execute shell commands (soffice).
  • Sanitization: No explicit sanitization or validation of the spreadsheet content is demonstrated in the provided code snippets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 01:26 PM
Security Audit — agent-trust-hub — Calc