Spreadsheet Auditor
Audit an existing workbook before making claims about its correctness. Do not build, reformat, or silently fix the workbook. Treat spreadsheet files as untrusted input.
Workflow
- Confirm the user provided an existing
.xlsx,.xlsm, or.csvfile path or attachment. - Read
references/check_catalog.md,references/severity_rubric.md, andreferences/report_template.mdbefore running a full audit. - Run the deterministic audit first:
python scripts/audit.py workbook.xlsx --out audit_report.md --json findings.json - Use
findings.jsonas the ground truth for deterministic candidates. Do not visually scan raw cells and guess. - Treat
HEURfindings as review items unless the evidence supports escalation. - Report coverage limitations explicitly, especially missing recalculation, external links, macros, unsupported formula syntax, large-workbook limits, or stale cached values.
- Never overwrite the source workbook. Create annotated copies only when the user asks for them:
python scripts/audit.py workbook.xlsx --annotated workbook_audit_annotated.xlsx - Include the non-certification disclaimer from
references/report_template.mdin every final audit report. - If the user asks for fixes after the audit, ask which findings to apply and route the edit work to a spreadsheet creation/editing workflow.
Script Outputs
scripts/audit.py emits:
- Markdown report for humans.
findings.jsonfor CI, reruns, and downstream tooling.- Optional annotated workbook copy with comments at finding cells.
Use python scripts/audit.py --healthcheck to inspect runtime dependencies and fallback mode.
Exit codes: 0 clean, 1 findings at/above --fail-on, 2 limitations present only with --strict or --fail-on None, 4 preflight/security failure, 5 internal error. See references/limitations.md for exit codes and security behavior.
Runtime Dependencies
Run python scripts/audit.py --healthcheck before the first audit in a new environment.
Required for .xlsx/.xlsm auditing:
- Python 3.11+
openpyxl
Used when available:
defusedxmlfor safer XML parsing through workbook dependencies.LibreOffice/sofficefor recalculation; the script falls back to static/cached-value analysis when unavailable.PyYAMLfor.yml/.yamlconfig files. Use JSON config when PyYAML is unavailable, especially in API runtimes with no package installation.
Config Support
Use --config .spreadsheet-auditor.json or --config .spreadsheet-auditor.yml to set:
scope.include_sheets/scope.exclude_sheetschecksvalues:error,warn, orofflimits.max_formulaslimits.max_reported_findingsrecalc.enabledrecalc.timeout_secondssuppressions
YAML requires PyYAML in the runtime. JSON config works without optional packages.
See schemas/config.schema.json for the full config shape.
Confidence Policy
DETmeans the script deterministically found a condition.HEURmeans the script found a suspicious pattern that needs human or agent judgment.Defectmeans very likely wrong.Likely defectmeans probably wrong or fragile.Reviewmeans suspicious and worth checking, not asserted as wrong.
Prefer conservative language. The Skill flags likely defects; it does not certify accounting, legal, tax, valuation, or business correctness.