trade-quote-builder

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes job specifications provided in YAML or JSON format and incorporates user-provided text (such as 'description' and 'notes') into the generated Excel (.xlsx) files. There is a potential vulnerability surface for CSV/spreadsheet injection if these fields contain characters like '=', '@', '+', or '-' that software might interpret as formulas.
  • Ingestion points: The script scripts/build_quote.py reads data from the input specification file (e.g., spec.yaml).
  • Boundary markers: No specific delimiters or validation logic is present to identify or sanitize embedded spreadsheet commands in the input data.
  • Capability inventory: The script scripts/build_quote.py performs file-write operations to the local filesystem using openpyxl.Workbook.save() for Excel files, reportlab.platypus.SimpleDocTemplate.build() for PDFs, and pathlib.Path.write_text() for JSON summaries. No network operations, subprocess executions, or dynamic code evaluations (exec/eval) are present.
  • Sanitization: The script does not currently sanitize or escape string fields before writing them into spreadsheet cells.
  • [EXTERNAL_DOWNLOADS]: The skill instructions and script docstrings recommend installing standard Python libraries (openpyxl, PyYAML, and reportlab) to enable full functionality.
  • Evidence: Documentation in SKILL.md and scripts/build_quote.py mentions the need for these packages and provides installation commands (e.g., pip install pyyaml). These are well-known, widely used packages in the Python ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 12:51 AM
Security Audit — agent-trust-hub — trade-quote-builder