xlsx-toolkit
Audit Microsoft Excel (.xlsx) workbooks for sheet count, cell count, formula density, external references, named ranges, hidden sheets, and data validation rules. Use when reviewing a financial model, sharing a workbook externally, or when the user mentions xlsx audit, spreadsheet review, formula audit, or workbook leakage check.
What this skill does
# Xlsx Toolkit Audit `.xlsx` files using the standard library only — no `openpyxl` required. Reads OOXML directly via `zipfile` + `xml.etree`. --- ## Table of Contents - [Keywords](#keywords) - [Quick Start](#quick-start) - [Core Workflows](#core-workflows) - [Tools](#tools) - [Reference Guides](#reference-guides) - [Templates](#templates) - [Best Practices](#best-practices) --- ## Keywords xlsx, Excel, spreadsheet, workbook, financial model, formula audit, hidden sheets, external references, named ranges, data validation --- ## Quick Start ```bash python scripts/xlsx_auditor.py model.xlsx ``` Outputs: sheet count and names, hidden-sheet count, cell count per sheet, formula count per sheet, external link count, named range count, data validation rule count. --- ## Core Workflows ### Workflow 1: Pre-Send Workbook Audit **Goal:** Catch the issues that embarrass the sender — leftover hidden sheets, broken external links, unused named ranges, formulas referencing local file paths. **Steps:** 1. Run audit 2. Hidden sheets > 0 → confirm intentional or delete 3. External links > 0 → verify links point to public / shared sources, not your local drive 4. Named-range count anomalies (very high) → likely cruft from prior model versions; clean up 5. Re-run until clean **Time Estimate:** 5-10 minutes per workbook. ### Workflow 2: Financial Model Review **Goal:** Quantify the rough complexity of a financial model before reading cell-by-cell. **Steps:** 1. Run audit; capture per-sheet cell counts and formula counts 2. Sheets with formula density > 70% are calculation sheets; should be well-structured 3. Sheets with formula density 0-10% are inputs; should be obviously labeled 4. Sheets with formula density 10-70% are mixed — easiest place for errors to hide 5. Cross-reference with `references/financial_model_audit_guide.md` **Time Estimate:** 30-60 minutes per model audit (audit + targeted reading). ### Workflow 3: Workbook Handoff Check **Goal:** Ensure a workbook handed off to another team or partner won't break on their machine. **Steps:** 1. Run audit 2. External links → re-link to shared paths (OneDrive, SharePoint, S3) or hard-code values 3. Custom named ranges → document if recipient is expected to extend; remove if internal 4. Macros (xlsm) → audit shows non-`.xlsx` extension expected; convert if recipient cannot run macros 5. File size > 10 MB → consider splitting or removing image / chart blobs **Time Estimate:** 10-20 minutes per workbook. --- ## Tools ### xlsx_auditor.py Reads a `.xlsx` file as a ZIP archive and parses OOXML directly. ```bash python scripts/xlsx_auditor.py model.xlsx python scripts/xlsx_auditor.py model.xlsx --json ``` **Reports:** - Sheet list with name, hidden status, cell count, formula count, formula density % - Total cell and formula counts - Named ranges and their scopes - External link references (file paths or URLs) - Data validation rule count - File size **Limits:** - Does **not** evaluate formulas. To check whether formulas are *correct*, use Excel itself or a financial-model-checker library. - Does **not** read cell values for non-shared-string cells beyond counting; full value extraction requires more parsing than this tool does. --- ## Reference Guides - **`references/financial_model_audit_guide.md`** — Patterns for auditing financial models; common error categories; defensive structure tips --- ## Templates - **`assets/workbook_handoff_checklist.md`** — Pre-send xlsx sign-off checklist --- ## Best Practices - **Hide internal-only sheets only when intended.** If a sheet is hidden because it's WIP, delete it before sending. - **Avoid external links across handoffs.** A formula referencing `'C:\Users\you\Desktop\old-model.xlsx'` is the workbook equivalent of leaving your laptop name in the document author field. - **Name your inputs.** Cells like `Inputs!B7` mean nothing. Named ranges like `WACC` and `RevenueGrowth` survive structural changes. - **One model, one purpose.** Workbooks that calculate, present, and serve as a database of records always end up broken. --- ## Integration Points - Pairs with `finance/` skills for financial-model review - Pairs with `c-level-advisor/cfo-advisor` for board-pack workbook review - Used by `data-analytics/` for ad-hoc analytics handoff
Related in Security
mac-ops
IncludedComprehensive macOS workstation operations — diagnose kernel panics, identify failing drives, audit launchd startup items, decode wake reasons, triage TCC permission denials, manage APFS snapshots, recover from no-boot. Use for: Mac is slow, slow bootup, won't boot, kernel panic, kernel_task hot, mds_stores CPU, photoanalysisd, cloudd, login loop, gray screen, sleep wake failure, drive failing, IO errors, APFS snapshots eating space, Time Machine local snapshots, Spotlight indexing, launchd, LaunchAgent, LaunchDaemon, login items, TCC permissions, Full Disk Access, Screen Recording denied, Gatekeeper, quarantine, com.apple.quarantine, app is damaged, helper tool, /Library/PrivilegedHelperTools, pmset, wake reasons, dark wake, sysdiagnose, panic.ips, DiagnosticReports, configuration profile, MDM profile, remote diagnostics over SSH.
a11y-audit
IncludedRun accessibility audits on web projects combining automated scanning (axe-core, Lighthouse) with WCAG 2.1 AA compliance mapping, manual check guidance, and structured reporting. Output is configurable: markdown report only, markdown plus machine-readable JSON, or markdown plus issue tracker integration. Use this skill whenever the user mentions "accessibility audit", "a11y audit", "WCAG audit", "accessibility check", "compliance scan", or asks to check a web project for accessibility issues. Also trigger when the user wants to verify WCAG conformance or map findings to a specific standard (CAN-ASC-6.2, EN 301 549, ADA/AODA).
erpclaw
IncludedAI-native ERP system with self-extending OS. Full accounting, invoicing, inventory, purchasing, tax, billing, HR, payroll, advanced accounting (ASC 606/842, intercompany, consolidation), and financial reporting. 413 actions across 14 domains, 43 expansion modules. Constitutional guardrails, adversarial audit, schema migration. Double-entry GL, immutable audit trail, US GAAP.
assess
IncludedAssesses and rates quality 0-10 across multiple dimensions (correctness, maintainability, security, performance, testability, simplicity) with pros/cons analysis. Compares against project conventions and prior decisions from memory. Produces structured evaluation reports with actionable improvement suggestions. Use when evaluating code, designs, architectures, or comparing alternative approaches.
spring-boot-security-jwt
IncludedProvides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.
code-hardcode-audit
IncludedDetect hardcoded values, magic numbers, and leaked secrets. TRIGGERS - hardcode audit, magic numbers, PLR2004, secret scanning.