minimax-xlsx
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes
subprocess.runinscripts/libreoffice_recalc.pyandscripts/xlsx_insert_row.pyto execute local utility scripts and the LibreOfficesofficebinary. These calls are essential for the skill's core functionality—such as formula recalculation and row shifting—and are implemented using secure coding practices, including passing arguments as lists to prevent shell injection. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from Excel and CSV files, which is a standard surface for indirect prompt injection.
- Ingestion points: Files are ingested through
xlsx_reader.pyandxlsx_unpack.pyfor analysis and editing. - Boundary markers: The skill uses specific XML tags and indices to structure data, and instructions include instructions to preserve existing workbook structures.
- Capability inventory: The agent can read/write local files and execute specific internal utility scripts via subprocess.
- Sanitization: The skill implements strong sanitization measures, including path traversal checks in
scripts/xlsx_unpack.pyand automatic XML entity escaping inscripts/shared_strings_builder.py. The presence of these safeguards reduces the risk associated with untrusted data ingestion.
Audit Metadata