enrich-excel

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill generates and executes AppleScript files and Python scripts at runtime to interface with Microsoft Excel. For example, it writes logic to /tmp/tf_read_excel.scpt before executing it with osascript.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it reads and acts upon untrusted content from the user's spreadsheet and external search results.
  • Ingestion points: Data enters the agent's context through cell values read in Step 1 and web snippets/page content fetched via the tinyfish tool in Step 3.
  • Boundary markers: The skill lacks explicit markers to delineate untrusted external data from its internal instructions.
  • Capability inventory: The skill possesses the ability to execute shell commands, run AppleScript, perform network requests, and write back to the local spreadsheet.
  • Sanitization: Content is processed without validation or sanitization, though basic string escaping is applied when writing values to Excel cells.
  • [DATA_EXFILTRATION]: The skill reads the contents of the active Excel workbook and sends derived queries to the tinyfish search service. This behavior is documented as the primary enrichment function and uses the vendor's provided CLI tool.
  • [COMMAND_EXECUTION]: The skill executes various system commands and vendor-provided CLI tools, including osascript for AppleScript execution and tinyfish for web searching and data retrieval.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 01:04 AM
Security Audit — agent-trust-hub — enrich-excel