Skip to content
Back to skills

Cm Xlsx

ASecurity

Usa esta skill cuando el usuario quiera crear, leer, editar o limpiar hojas de cálculo (.xlsx, .xlsm, .xltx, .csv, .tsv): añadir columnas, calcular fórmulas, dar formato, hacer gráficos, o reestructurar datos desordenados. El entregable debe ser un archivo de hoja de cálculo.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 4, 2026
educationpythonrustgoshellbashnode

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 19 files and shows the line behind each finding

Scanned October 4, 2026

npx -y skills add Chemrog/Chatmu-Skills --skill cm-xlsx --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cm Xlsx?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cm Xlsx
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chemrog-cm-xlsx/badge)](https://www.skillsdirectory.com/skills/chemrog-cm-xlsx)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cm-xlsx
category: creative
version: "1.0"
shortDesc: "Crear, leer y editar hojas de cálculo Excel (.xlsx/.csv) con fórmulas y formato."
description: "Usa esta skill cuando el usuario quiera crear, leer, editar o limpiar hojas de cálculo (.xlsx, .xlsm, .xltx, .csv, .tsv): añadir columnas, calcular fórmulas, dar formato, hacer gráficos, o reestructurar datos desordenados. El entregable debe ser un archivo de hoja de cálculo."
tags: ["xlsx", "excel", "spreadsheet", "csv", "openpyxl", "pandas"]
requiresTools: ["execute_python"]
license: Proprietary. LICENSE.txt has complete terms
---

## Chatmu execution environment (overrides all local-execution instructions below)

You do NOT run Python, Node, or shell commands directly. Every script or command in this skill must be executed by calling the `execute_python` tool with the code as a string.

**File conventions inside the sandbox:**
- Input files uploaded by the user arrive at `/workspace/in/<filename>`. Use those absolute paths when reading.
- Write ALL output files to `/workspace/out/<name>.<ext>`. The tool returns anything under `/workspace/out/` as a downloadable artifact to the user.
- Ignore any instruction below that says "run this script", "python foo.py", "use a notebook", or references `/tmp/`, `./output/`, or relative paths — translate those to `/workspace/in/` for reads and `/workspace/out/` for writes, and wrap the logic in an `execute_python` call.
- Helper scripts shipped with this skill (in `scripts/`, `references/`, etc.) must be uploaded to the sandbox alongside the user's file via the tool's `inputFiles` parameter with a `workspacePath` under `/workspace/in/` so the executed code can import or read them.
- `openpyxl`, `pandas`, `pypdf`, `python-docx`, `python-pptx`, `markitdown`, and `matplotlib` are preinstalled in the sandbox. Do not run `pip install` unless an import actually fails.

---


# XLSX creation, editing, and analysis

| Task | Approach |
|---|---|
| **Create** or **edit** with formulas/formatting | `openpyxl` — see gotchas below |
| **Bulk data** in or out | `pandas` (`read_excel`, `to_excel`) |
| **Quick look** at a sheet | `markitdown file.xlsx` — `## SheetName` per sheet; reads `.xlsm` too. No cell coordinates, so don't plan edits from it |
| **Read** a model (formulas *and* values) | two `load_workbook` passes — see gotchas |

> `openpyxl`, `pandas`, and `markitdown` are preinstalled — do not run `pip install` first; write the script and import directly. Only if an import fails (or the `markitdown` command is missing): `pip install` the missing package.

> Script paths below are relative to this skill's directory.

## Requirements for every output

- **Professional font** (Arial, Times New Roman) throughout, unless the user says otherwise.
- **Zero formula errors.** Never ship while `recalc.py` reports `errors_found`. If you think an error predates you, prove it: load the *original* with `data_only=True` and look at that cell. An error you introduced looks exactly like one you inherited.
- **Use formulas, never hardcoded results.** Write `sheet['B10'] = '=SUM(B2:B9)'`, not the Python-computed total. The sheet must recalculate when its inputs change.
- **Follow the user's spec literally.** Exact tab names, exact column headers, and the formula they spelled out. A redesign that computes something else fails, however elegant.
- **Document every assumption and hardcoded number** where the reader will see it — a cell comment, or an adjacent cell at a table's end. Cite a real source when one exists (`Source: Company 10-K, FY2024, Page 45, Revenue Note, [SEC EDGAR URL]`); when the number came from the user, say so plainly.
- **A workbook *you create* for someone to fill in** needs a short legend naming which cells to edit, and one example row of realistic values showing the expected format. Never add such a row to a file you were asked to edit.
- **Editing an existing file: match its conventions exactly.** They override every guideline here. Find its designated input cells first — a distinct font color, fill, or shading marks them — write only there, and leave every existing formula untouched.

## Recalculate (mandatory whenever the file contains formulas)

openpyxl writes formulas as strings with **no cached values**. Until you recalculate, every
formula cell reads back as `None` to anything reading cached values — `pandas`,
`load_workbook(data_only=True)`, and most previewers.

```bash
python scripts/recalc.py output.xlsx [timeout_seconds]   # default 30
```

LibreOffice computes every formula, the file is **rewritten in place**, and you get JSON:
`status` (`success` | `errors_found`), `total_formulas`, `total_errors`, and an
`error_summary` naming up to 100 cells per error type (`locations_truncated` says how many it
withheld — trust `total_errors`, not the length of the list). Fix what it names and run it
again. **JSON with an `error` key instead of a `status` means nothing was recalculated**, and
only that case exits non-zero — `errors_found` exits 0, so never treat a clean exit as a clean
workbook.

**A green recalc proves your formulas *evaluate*, not that they are *right*.** An off-by-one
range or a reference to the wrong row yields a clean, error-free file with wrong numbers.
Write 2–3 formulas first and check they pull the values you expect, before building out a grid.

**A workbook that links to another file loses those links** if you re-save it with openpyxl and
then recalculate. Such a formula reads `='[1]Returns Analysis'!$B$2` — the `[1]` is an index
into the workbook's external-reference list, naming a *separate file on disk*, not a sheet.
That file is rarely present here, so the cell's cached value is the only thing holding its
data. openpyxl strips that value on save; LibreOffice then has to resolve the reference for
real, fails, writes `#NAME?`, and deletes every link. `recalc.py` refuses to run in that state
— copy those cells' values out of the original before you save over them (`--force` overrides,
and accepts the loss).

## Choosing formulas that survive verification

LibreOffice implements fewer functions than Excel, and one it cannot evaluate becomes a
literal `#NAME?` baked into the file you deliver.

- **Prefer Excel-2007-era functions** — `SUMIFS`, `INDEX`, `MATCH`, `IFERROR`, `SUMPRODUCT` — which need no prefix.
- **Six post-2007 functions work, but only with an `_xlfn.` prefix**, because openpyxl writes your formula into the XML verbatim and Excel stores post-2007 names prefixed (its UI hides the prefix): `_xlfn.TEXTJOIN`, `_xlfn.CONCAT`, `_xlfn.IFS`, `_xlfn.SWITCH`, `_xlfn.MAXIFS`, `_xlfn.MINIFS`. Written bare, each yields `#NAME?`.
- **Never use `XLOOKUP`, `XMATCH`, `SORT`, `FILTER`, `UNIQUE`, or `SEQUENCE`.** The runtime's LibreOffice cannot evaluate them under *any* prefix. Newer builds do evaluate them, but they are spilling array functions and an openpyxl-written file has no spill metadata, so only the top-left cell of the range gets a value — and `recalc.py` reports `total_errors: 0` on the truncated result. Use `INDEX`/`MATCH` for lookups, and sort, filter, and de-duplicate in Python before writing the cells.
- A formula LibreOffice could not parse is written back **lowercased** — a quick tell beside a `#NAME?`.

## openpyxl gotchas

- **Reading a model takes two loads.** `data_only=True` yields cached values with the formulas gone; the default yields formula strings with no values. One pass cannot give you both.
- **`data_only=True` is destructive if you save.** That workbook has no formulas left, so saving replaces every one with a literal — permanently.
- **`data_only=True` on a file openpyxl just wrote returns `None` everywhere** — run `recalc.py` first. (A formula whose result is `""` also reads back as `None`.)
- **Merged cells: write the top-left anchor only.** Every other cell in the range is a `MergedCell` whose `.value` is read-only.
- **`.xlsm` loses its macros unless you pass `keep_vba=True`** to `load_workbook`.
- **A sheet name containing a space must be quoted** in a cross-sheet reference: `='Assumptions Inputs'!$B$5`. Unquoted, it evaluates to `#VALUE!`.

## Financial models

Unless the user says otherwise, or the existing file already does something else.

**Color:** blue text (`0,0,255`) for hardcoded inputs and scenario levers · black for formulas ·
green (`0,128,0`) for links to another sheet · red (`255,0,0`) for links to another file ·
yellow fill (`255,255,0`) for key assumptions and cells the user should fill in.

**Numbers:** currency `$#,##0`, with the unit named in the header (`Revenue ($mm)`) · zeros
render as `-`, including in percentages (`$#,##0;($#,##0);-`) · negatives in parentheses ·
percentages `0.0%`, **stored as fractions** (`0.15` renders `15.0%`; storing `15` renders
`1500.0%`) · valuation multiples `0.0x` · years as text (`"2024"`, never `2,024`).

**Structure:** every assumption in its own labeled cell, referenced by the formulas that use it
(`=B5*(1+$B$6)`, never `=B5*1.05`) · formulas consistent across every projection period, since a
lone edited cell mid-row is the commonest silent error · guard denominators that can be zero.

## Dependencies

`openpyxl`, `pandas`, `markitdown` (pip, preinstalled — install only if an import fails or the command is missing) · LibreOffice (`soffice`, auto-configured for sandboxed environments via `scripts/office/soffice.py`)

Files in this skill

  • LICENSE.txt1.4 KB
  • SKILL.md9.2 KB
  • scripts/office/helpers/__init__.py3.3 KB
  • scripts/office/helpers/pptx_chart.py5.7 KB
  • scripts/office/helpers/pptx_slide.py1.6 KB
  • scripts/office/helpers/pptx_theme.py3.4 KB
  • scripts/office/schemas/ISO-IEC29500-4_2016/dml-chart.xsd73.2 KB
  • scripts/office/schemas/ISO-IEC29500-4_2016/dml-chartDrawing.xsd6.8 KB
  • scripts/office/schemas/ISO-IEC29500-4_2016/dml-diagram.xsd50.1 KB
  • scripts/office/schemas/ISO-IEC29500-4_2016/dml-lockedCanvas.xsd624 B
  • scripts/office/schemas/ISO-IEC29500-4_2016/dml-picture.xsd1.2 KB
  • scripts/office/schemas/ISO-IEC29500-4_2016/dml-spreadsheetDrawing.xsd8.7 KB
  • scripts/office/schemas/ISO-IEC29500-4_2016/dml-wordprocessingDrawing.xsd14.4 KB
  • scripts/office/schemas/ISO-IEC29500-4_2016/pml.xsd81.7 KB
  • scripts/office/schemas/ISO-IEC29500-4_2016/shared-additionalCharacteristics.xsd1.2 KB
  • scripts/office/schemas/ISO-IEC29500-4_2016/shared-bibliography.xsd7.2 KB
  • scripts/office/schemas/ISO-IEC29500-4_2016/shared-commonSimpleTypes.xsd6.2 KB
  • scripts/office/schemas/ISO-IEC29500-4_2016/shared-customXmlDataProperties.xsd1.2 KB
  • scripts/office/schemas/ISO-IEC29500-4_2016/shared-customXmlSchemaProperties.xsd880 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…