skills/mrgoonie/claudekit-skills/xlsx/Gen Agent Trust Hub

xlsx

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The recalc.py utility script executes system commands such as soffice (LibreOffice) and timeout/gtimeout. These calls are used to trigger headless spreadsheet recalculation and manage process execution time, which are necessary steps for verifying formula results.
  • [DYNAMIC_EXECUTION]: On its first run, recalc.py generates a LibreOffice Basic macro file (Module1.xba) from a hardcoded template and saves it to the user's application configuration directory. This macro is subsequently invoked by the skill to automate the recalculation and saving of Excel workbooks.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external spreadsheet files (.xlsx, .csv, etc.) using pandas and openpyxl. This ingestion of untrusted data constitutes an attack surface for indirect prompt injection. The skill provides mitigation through mandatory formula verification and detailed instructions for identifying Excel error states (#REF!, #VALUE!, etc.) that could indicate malformed or malicious data inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:15 AM
Security Audit — agent-trust-hub — xlsx