xlsx

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill leverages industry-standard and trusted libraries, specifically pandas and openpyxl, for its core spreadsheet manipulation and data analysis functionality.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local Python script (scripts/recalc.py) to handle Excel formula recalculation via LibreOffice. This is a legitimate and scoped use of command execution necessary for the spreadsheet model to function correctly, and it does not involve untrusted remote sources.
  • [REMOTE_CODE_EXECUTION]: The skill references local helper scripts (scripts/recalc.py and scripts/office/soffice.py) included within its own package to manage environment-specific tasks like LibreOffice configuration in sandboxes. No execution of code from external or unverifiable remote URLs was identified.
  • [DATA_EXPOSURE]: The skill's primary function involves processing external spreadsheet files, which represents an indirect prompt injection surface. However, this is inherent to the skill's purpose, and the instructions focus on structured data handling, formula verification, and error checking, minimizing the risk of accidental obedience to malicious instructions embedded in data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 01:28 PM
Security Audit — agent-trust-hub — xlsx