trade-quote-builder
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes job specifications provided in YAML or JSON format and incorporates user-provided text (such as 'description' and 'notes') into the generated Excel (.xlsx) files. There is a potential vulnerability surface for CSV/spreadsheet injection if these fields contain characters like '=', '@', '+', or '-' that software might interpret as formulas.
- Ingestion points: The script
scripts/build_quote.pyreads data from the input specification file (e.g.,spec.yaml). - Boundary markers: No specific delimiters or validation logic is present to identify or sanitize embedded spreadsheet commands in the input data.
- Capability inventory: The script
scripts/build_quote.pyperforms file-write operations to the local filesystem usingopenpyxl.Workbook.save()for Excel files,reportlab.platypus.SimpleDocTemplate.build()for PDFs, andpathlib.Path.write_text()for JSON summaries. No network operations, subprocess executions, or dynamic code evaluations (exec/eval) are present. - Sanitization: The script does not currently sanitize or escape string fields before writing them into spreadsheet cells.
- [EXTERNAL_DOWNLOADS]: The skill instructions and script docstrings recommend installing standard Python libraries (
openpyxl,PyYAML, andreportlab) to enable full functionality. - Evidence: Documentation in
SKILL.mdandscripts/build_quote.pymentions the need for these packages and provides installation commands (e.g.,pip install pyyaml). These are well-known, widely used packages in the Python ecosystem.
Audit Metadata