spreadsheet-model-auditor
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The
audit_xlsx.pyscript utilizessubprocess.runto invoke thesoffice(LibreOffice) binary for headless recalculation and conversion of spreadsheets. This is implemented securely using argument lists rather than shell strings, and is a core function of the tool.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from user-provided Excel files (Ingestion points:scripts/audit_xlsx.py). The script extracts formulas and values for analysis. The risk of the agent misinterpreting spreadsheet content as instructions is mitigated by the structured output format where formulas are wrapped in Markdown backticks (Boundary markers). The skill possesses capabilities to execute a Python script that performs file operations and invokes external binaries (Capability inventory:subprocess.run,openpyxl). Sanitization is handled by the script's reporting logic which distinguishes data from report structure (Sanitization).\n- [EXTERNAL_DOWNLOADS]: The tool relies on theopenpyxlPython package. This is a standard, well-known library for interacting with Excel files and is considered a safe dependency.
Audit Metadata