spreadsheet-model-auditor

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The audit_xlsx.py script utilizes subprocess.run to invoke the soffice (LibreOffice) binary for headless recalculation and conversion of spreadsheets. This is implemented securely using argument lists rather than shell strings, and is a core function of the tool.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from user-provided Excel files (Ingestion points: scripts/audit_xlsx.py). The script extracts formulas and values for analysis. The risk of the agent misinterpreting spreadsheet content as instructions is mitigated by the structured output format where formulas are wrapped in Markdown backticks (Boundary markers). The skill possesses capabilities to execute a Python script that performs file operations and invokes external binaries (Capability inventory: subprocess.run, openpyxl). Sanitization is handled by the script's reporting logic which distinguishes data from report structure (Sanitization).\n- [EXTERNAL_DOWNLOADS]: The tool relies on the openpyxl Python package. This is a standard, well-known library for interacting with Excel files and is considered a safe dependency.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 12:51 AM
Security Audit — agent-trust-hub — spreadsheet-model-auditor