spreadsheet-qa
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from CSV and XLSX files. While these files are processed using structured SQL and pandas logic, the agent's review of sample rows or data profiles could be targeted by malicious instructions embedded in the cell values.
- Ingestion points:
scripts/profile.pyandscripts/ask.pyingest data from user-provided file paths for profiling and querying. - Boundary markers: The skill explicitly requires a multi-step workflow including profiling, metric definition, and reconciliation to verify results before answering.
- Capability inventory: The skill utilizes
duckdbandsqlite3for local data processing,pandasfor data manipulation, and filesystem access to read/write data files. - Sanitization: Input data is loaded as text to prevent auto-typing vulnerabilities, and the workflow requires explicit casting and row-count verification.
- [SAFE]: The skill demonstrates high-quality security practices. It performs computations in a controlled local environment, uses well-known libraries, and provides auditing tools (
diff_edit.py) to verify that data edits only affect intended cells. No evidence of data exfiltration or privilege escalation was found.
Audit Metadata