Calc
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous shell commands for automating LibreOffice Calc, including starting the application in headless mode and performing batch conversions between ODS, XLSX, CSV, and PDF formats using the
sofficebinary. - [EXTERNAL_DOWNLOADS]: Instructions include the installation of standard Python libraries from official registries, specifically
ezodf,odfpy, andpandas, to handle spreadsheet manipulation and data analysis. - [INDIRECT_PROMPT_INJECTION]: The skill represents an attack surface for indirect prompt injection as it is designed to ingest and process data from external spreadsheet formats (ODS, XLSX, CSV).
- Ingestion points: Data is loaded into the agent's context through libraries like
ezodfand the LibreOffice UNO API (doc.getSheets().getByIndex(0)). - Boundary markers: None provided in the sample scripts to differentiate between data and instructions.
- Capability inventory: The skill has capabilities to write files (
doc.save,doc.storeToURL) and execute shell commands (soffice). - Sanitization: No explicit sanitization or validation of the spreadsheet content is demonstrated in the provided code snippets.
Audit Metadata