spreadsheets
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes local command-line tools such as
qsv,DuckDB, andLibreOfficeviasubprocess.runcalls in its helper scripts (peek.py,profile.py, andrecalc.py). These executions are used exclusively for data analysis and transformation tasks, using list-based arguments to ensure safe handling of file paths and delimiters. - [DYNAMIC_EXECUTION]: In
recalc.py, the skill generates a temporary StarBasic macro and executes it within a headless LibreOffice instance to perform spreadsheet recalculation. The macro is hardcoded to perform only benign operations: calculating formulas, saving the workbook, and closing the application. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external spreadsheet data, which is an inherent vector for CSV injection or indirect prompt injection. The skill mitigates this through a mandatory evidence chain: it identifies ingestion points in
peek.pyandprofile.py, establishes trust boundaries inSKILL.md, and provides explicit sanitization rules (Invariant 6) to escape formula-prefix characters (=,+,@) in external datasets.
Audit Metadata