xlsx
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates reading and parsing external XLSX files, which serves as an ingestion point for untrusted data. Instructions embedded within these files could potentially influence agent behavior.
- Ingestion points: Workflow 2 ('Spreadsheet Data Extraction') and Quick Start instructions for reading XLSX files in SKILL.md.
- Boundary markers: Not explicitly defined for separating data from instructions.
- Capability inventory: Mentions data extraction and report generation capabilities using Node.js and Python libraries across SKILL.md.
- Sanitization: The skill recommends data validation and cleaning in the extraction workflow, but does not provide specific guidance on mitigating prompt injection risks.
Audit Metadata