xlsx
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The
recalc.pyscript executes system commands usingsubprocess.runto interact with LibreOffice (soffice) and system timeout utilities. While necessary for the skill's recalculation feature, this involves programmatic interaction with external system binaries. - [METADATA_POISONING]: There is a discrepancy between the reported author ('spacezephyr') and the copyright notice in
LICENSE.txt('Anthropic, PBC'). This inconsistency in metadata could be misleading regarding the origin and ownership of the skill. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external Excel, CSV, and TSV files, which serves as an ingestion point for potentially malicious instructions embedded in spreadsheet content.
- Ingestion points: The
SKILL.mddocumentation instructs the agent to usepd.read_excel()andload_workbook()to ingest data from external files into the agent's context. - Boundary markers: The instructions do not provide specific delimiters or ignore-instructions for the agent when processing data from spreadsheets, increasing the risk of the agent following instructions found within cells.
- Capability inventory: The skill has the capability to read and write local files and execute system commands through the
recalc.pyscript. - Sanitization: There is no evidence of data validation or sanitization logic to filter out natural language instructions from the spreadsheet data being processed.
Audit Metadata