Agent skill

Spreadsheet Model Auditor

by OneWave-AI in OneWave-AI/claude-skills

Audits business spreadsheet models (.xlsx, .xlsm, or Google Sheets exported to .xlsx) for structural integrity errors and explains each fix -- budgets, forecasts, pricing models, commission…

MITAuto-check passedDocuments & Office

Install Spreadsheet Model Auditor

skills CLI
$ npx skills add OneWave-AI/claude-skills --skill spreadsheet-model-auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install OneWave-AI/claude-skills spreadsheet-model-auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/OneWave-AI/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/spreadsheet-model-auditor .claude/skills/spreadsheet-model-auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
spreadsheet-model-auditor
GitHub stars
328
Token cost
~2k tokens
SKILL.md length
929 words
Files
7 (incl. scripts, references)
Skills in repo
69
Repo updated
First seen
Licence
MIT

At a glance

Audits business spreadsheet models (.xlsx, .xlsm, or Google Sheets exported to .xlsx) for structural integrity errors and explains each fix -- budgets, forecasts, pricing models, commission…

  • Works in 5 steps: Get an .xlsx → Run the script → Triage the findings → …
  • Tasks that involve Excel spreadsheets
  • SKILL.md covers Workflow, What the script cannot catch, Rules and Files
  • Runs Python scripts from its folder; calls soffice, python3 and pip

What it does

Spreadsheet Model Auditor is an agent skill from OneWave-AI/claude-skills. Audits business spreadsheet models (.xlsx, .xlsm, or Google Sheets exported to .xlsx) for structural integrity errors and explains each fix -- budgets, forecasts, pricing models, commission calculators, FP&A packs, ops trackers, not only banking models. A bundled openpyxl script finds hardcoded numbers inside formulas, typed values pasted over formulas, inconsistent formulas across a row or column,

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts and reference files (for example `examples/worked-example.md`, `references/error-catalog.md` and `references/google-sheets.md`).

It sits in Documents & Office, covering Excel spreadsheets. It works with Microsoft Excel, openpyxl, Google Sheets and LibreOffice. The repository describes itself as: 200+ production-ready Claude Code skills for sales, marketing, design, engineering, and AI agent architecture. Built and maintained by OneWave AI. The licence is MIT.

When your agent uses it

  • Tasks that involve Excel spreadsheets

Example prompts

  • “Use the spreadsheet-model-auditor skill to audit business spreadsheet models (.xlsx, .xlsm, or Google Sheets exported to .xlsx) for structural…”
  • “/spreadsheet-model-auditor”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Get an .xlsx
  2. Run the script
  3. Triage the findings
  4. Review what the script cannot judge
  5. Report

What it can do on your machine

Read from SKILL.md and the folder at commit fc5b785. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • soffice
    • python3
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Spreadsheet Model Auditor loads about 2k tokens when it runs, and up to ~6.1k if it reads all its reference files. Until then it costs about 107 tokens; SKILL.md has 929 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from OneWave-AI/claude-skills at commit fc5b785, republished under its MIT licence (© OneWave-AI). 929 words, ~1,957 tokens.

Download SKILL.mdSave it as .claude/skills/spreadsheet-model-auditor/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
spreadsheet-model-auditor
description
Audits business spreadsheet models (.xlsx, .xlsm, or Google Sheets exported to .xlsx) for structural integrity errors and explains each fix -- budgets, forecasts, pricing models, commission calculators, FP&A packs, ops trackers, not only banking models. A bundled openpyxl script finds hardcoded numbers inside formulas, typed values pasted over formulas, inconsistent formulas across a row or column,

Spreadsheet Model Auditor

Models look right when you read them cell by cell. Structural errors -- a SUM that stopped one row short, a formula overwritten with a typed number in month 7, a rate hardcoded in one copy of a formula -- are invisible to eyeballing and are exactly what gets people fired over a board number. Do not audit by reading the grid. Run the script, which reads every formula, then spend human judgment on what a script cannot know: whether the assumptions are sane.

Workflow

1. Get an .xlsx
  • Excel file: use it directly (.xlsx or .xlsm). Legacy .xls: convert first with soffice --headless --convert-to xlsx file.xls.
  • Google Sheets: File > Download > Microsoft Excel (.xlsx). Read references/google-sheets.md for which Sheets functions survive export and what to check manually.
  • CSV is not a model. It has no formulas; there is nothing structural to audit. Ask for the workbook.
2. Run the script
bash
python3 scripts/audit_xlsx.py model.xlsx --json audit.json --md audit.md

Add --recalc when the report says cached values: NO. That happens when the file was written by a script, a BI export, or any tool that does not calculate: openpyxl can read formulas from any file, but stored results exist only if Excel (or LibreOffice) calculated and saved it. --recalc runs soffice --headless --convert-to xlsx on a copy so error, footing, and stale-value checks can run. Without LibreOffice the script still runs every formula-based check and says which value checks it skipped -- never report "no errors" for a check that was skipped.

Needs only openpyxl (pip install openpyxl). It handles 50k-formula workbooks in a few seconds.

3. Triage the findings

Read audit.md. Findings are ranked critical > high > medium > low > info, each with the cell, the formula, why it matters, and the fix. Before presenting:

  • Open the cited cells yourself (the JSON has the formula). Confirm each critical and high finding is real in context; drop or downgrade what is clearly intentional (a labeled override row, a deliberate plug with a note).
  • Collapse repeats. Twelve sum_range_omission findings across B11:M11 are one problem: "Total opex omits the Software row in every month."
  • Trace the dollar impact of the top findings where you can: "Total opex is understated by 1,200/month, 14,400/year, so operating income is overstated by the same."
  • error_value lists root causes only; propagated errors clear when the root is fixed.

The full list of checks, with examples and fixes, is in references/error-catalog.md. Read it when a finding type is unfamiliar or the user asks what a check means.

4. Review what the script cannot judge

Structural integrity is necessary, not sufficient. A perfectly built model with a 40% monthly growth rate is still wrong. Always do this pass and label it as judgment, not detection:

  • Assumptions. List every input on the inputs sheet (or every typed number feeding formulas). For each: is it plausible for this business, sourced, and dated? Flag growth rates that compound to absurd annual numbers (3%/month is 43%/year), churn and conversion rates outside normal ranges, prices that disagree with the stated price list.
  • Units and periods. Monthly vs annual rates mixed (an annual salary divided by 12 in one row and not another), thousands vs units, percentages typed as whole numbers, fiscal vs calendar periods, a 13th month or a missing one.
  • Sign conventions. Costs positive-and-subtracted or negative-and-added, consistently. Check that every total's arithmetic matches the convention.
  • Timing. Does cash follow the stated terms (net-30 revenue should not land the same month)? Do annual costs hit the right month?
  • Sensitivity of the top 3 drivers. Identify the three inputs that move the headline output most (usually volume, price, and the largest cost). State the output at +/-10% on each, computed from the model's own structure. If the conclusion flips inside that range, say so -- that is the most useful sentence in the audit.
  • Does it answer the question? A forecast with no cash line, a commission calc that ignores clawbacks, a pricing model with no volume discount: note what is missing.
Show full SKILL.md (274 more words)Show less
5. Report

Use this shape. Lead with the verdict, not the method.

## Verdict
<Trustworthy / Usable after fixes / Do not use>, in one or two sentences with the
dollar impact of the worst problem.

## Must fix (critical + high)
1. <Sheet!Cell> -- <what is wrong in plain words> -- <impact> -- <exact fix>

## Should fix (medium)
## Worth knowing (low / info, grouped)

## Assumption review (judgment, not detected)
<table: input, value, concern, suggested range or question for the owner>

## Sensitivity
<top 3 drivers, output at -10% / base / +10%>

## Not checked
<anything skipped: no cached values, INDIRECT targets, macros, pivot tables>

Offer to fix the workbook when the user wants it: make the changes with openpyxl on a copy (never overwrite the original), re-run the audit on the copy, and show the before/after finding counts.

What the script cannot catch

Say these limits out loud when relevant instead of implying a clean bill of health:

  • Wrong logic that is internally consistent (the wrong formula copied correctly across all 12 months).
  • Wrong assumptions, wrong units, wrong source data.
  • Targets of INDIRECT and OFFSET (they are flagged, but their precedents are invisible), macros/VBA, Power Query, pivot table sources, data validation, conditional formatting logic.
  • Values when the file has no cached results and LibreOffice is unavailable.
  • LibreOffice recalculation is close to Excel but not identical for newer functions (LAMBDA, some dynamic arrays); treat value-based findings on those cells with care.

Rules

  • Cite every finding by Sheet!Cell. A finding without an address cannot be fixed.
  • Never call a model "correct". The strongest claim is "no structural errors found by these checks", plus the assumption review.
  • Separate detected (script) from judged (you). Readers weigh them differently.
  • Business-neutral language: explain why it matters in terms of the decision the model drives (budget approval, price change, payout), not spreadsheet jargon.
  • Do not modify the user's file unless asked, and then only a copy.

Files

  • scripts/audit_xlsx.py -- the auditor (JSON + markdown output).
  • references/error-catalog.md -- every check: example, why it matters, fix, false-positive notes.
  • references/google-sheets.md -- exporting from Sheets and Sheets-only functions.
  • examples/worked-example.md -- a full run on a broken operating model, from script output to final report.
  • tests/build_fixtures.py, tests/run_tests.py -- planted-error fixtures and the regression test.

© OneWave-AI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in spreadsheet-model-auditor of OneWave-AI/claude-skills.

  • SKILL.md
  • examples/worked-example.md
  • references/error-catalog.md
  • references/google-sheets.md
  • scripts/audit_xlsx.py
  • tests/build_fixtures.py
  • tests/run_tests.py

Open the folder on GitHubat commit fc5b785

Compare with similar skills

Spreadsheet Model Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Spreadsheet Model Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Spreadsheet Model Auditor this skillOneWave-AI/claude-skills328—~2kAutomated safety check: PassMIT
XLSX Spreadsheet ToolkitXiaomiMiMo/MiMo-Code14k—~2.9kAutomated safety check: PassApache-2.0
XLSXNousResearch/hermes-agent252k—~2.4kAutomated safety check: PassMIT
Excel Spreadsheet Builderagentscope-ai/QwenPaw36k—~1.8kAutomated safety check: PassProprietary
XLSXjjyaoao/HelloAgents3.2k—~5kAutomated safety check: PassProprietary
XLSXginlix-ai/LangAlpha1.8k—~9.3kAutomated safety check: PassApache-2.0

Similar skills

  • XLSX Spreadsheet Toolkit

    XiaomiMiMo/MiMo-Code

    Builds, edits, cleans, recalculates and reads Excel workbooks and CSV files with openpyxl and pandas, plus LibreOffice for recalculation and PDF export.

    14k GitHub stars~2.9k tokensUpdated today
    Documents & OfficeAuto-check passed
  • XLSX

    NousResearch/hermes-agent

    Create, read, edit Excel .xlsx workbooks and CSVs. An agent skill from NousResearch/hermes-agent.

    252k GitHub stars~2.4k tokensUpdated today
    Documents & OfficeAuto-check passed
  • Excel Spreadsheet Builder

    agentscope-ai/QwenPaw

    Creates, edits, cleans and analyzes Excel and CSV files with openpyxl and pandas, recalculating formulas through LibreOffice so files are delivered without formula errors.

    36k GitHub stars~1.8k tokensUpdated today
    Documents & OfficeAuto-check passed
  • XLSX

    jjyaoao/HelloAgents

    Comprehensive spreadsheet creation, editing, and analysis with support for formulas, formatting, data analysis, and visualization.

    3.2k GitHub stars~5k tokensUpdated 3 days ago
    Documents & OfficeAuto-check passed
  • XLSX

    ginlix-ai/LangAlpha

    Excel workbooks with live formulas: build or edit .xlsx models with openpyxl, recalculate with IronCalc or LibreOffice, audit conventions, profile messy uploads, render for review

    1.8k GitHub stars~9.3k tokensUpdated today
    Documents & OfficeAuto-check passed
  • CSV Formula Injection

    yaklang/hack-skills

    CSV/spreadsheet formula injection (DDE, Excel/LibreOffice, Google Sheets IMPORT).

    2.4k GitHub stars~1.1k tokensUpdated 26 days ago
    Documents & OfficeAuto-check passed

More from OneWave-AI/claude-skills

All 69 skills in this repo
  • CRM Data Cleanup

    OneWave-AI/claude-skills

    Finds duplicate and junk records in a CRM CSV export with fuzzy matching, normalizes fields and writes a reviewable merge plan plus import-ready files without touching the live CRM.

    328 GitHub stars~2.5k tokensUpdated 7 days ago
    Auto-check passed
  • Design Export Repair

    OneWave-AI/claude-skills

    Repairs broken decks and PDFs exported from Claude Design or similar AI deck generators: clipped text, wrong fonts and corrupted .pptx package structure.

    328 GitHub stars~2.6k tokensUpdated 7 days ago
    Auto-check passed
  • Bi Measure Builder

    OneWave-AI/claude-skills

    Writes, explains, debugs, and optimizes BI calculations - Power BI / Fabric DAX measures and calculated columns, Tableau calculated fields (FIXED/INCLUDE/EXCLUDE LOD expressions, table…

    328 GitHub stars~2.2k tokensUpdated 7 days ago
    Auto-check passed
  • Bookkeeping Close

    OneWave-AI/claude-skills

    Categorizes transactions, reconciles bank and card statements to the ledger, works a month-end checklist and prepares a close package, without ever forcing a balance.

    328 GitHub stars~2k tokensUpdated 7 days ago
    Auto-check passed
  • CSV and Excel Merger

    OneWave-AI/claude-skills

    Combines CSV, TSV and Excel files into one verified table with pandas, by stacking or joining, mapping columns, normalizing keys and removing duplicates.

    328 GitHub stars~1.6k tokensUpdated 7 days ago
    Auto-check passed
  • Sec Filing Puller

    OneWave-AI/claude-skills

    Pulls financial statement numbers for US public companies straight from SEC EDGAR's free official XBRL APIs (companyfacts, companyconcept, frames, submissions) into a cited table.

    328 GitHub stars~2.1k tokensUpdated 7 days ago
    Auto-check passed

Questions about Spreadsheet Model Auditor

What does Spreadsheet Model Auditor do?

Audits business spreadsheet models (.xlsx, .xlsm, or Google Sheets exported to .xlsx) for structural integrity errors and explains each fix -- budgets, forecasts, pricing models, commission…. Spreadsheet Model Auditor is an agent skill from OneWave-AI/claude-skills.xlsx) for structural integrity errors and explains each fix -- budgets, forecasts, pricing models, commission calculators, FP&A packs, ops trackers, not only banking models.

When should I use Spreadsheet Model Auditor?

Spreadsheet Model Auditor fits situations like: tasks that involve Excel spreadsheets.

How do I install Spreadsheet Model Auditor in Claude Code?

Run `npx skills add OneWave-AI/claude-skills --skill spreadsheet-model-auditor -a claude-code`. Or copy the skill folder (spreadsheet-model-auditor in OneWave-AI/claude-skills) into .claude/skills/spreadsheet-model-auditor in your project. Claude Code loads it when a task matches its description.

How do I install Spreadsheet Model Auditor in Codex?

Run `npx skills add OneWave-AI/claude-skills --skill spreadsheet-model-auditor -a codex`. Or copy the skill folder (spreadsheet-model-auditor in OneWave-AI/claude-skills) into .agents/skills/spreadsheet-model-auditor in your project. Codex loads it when a task matches its description.

Can I use Spreadsheet Model Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OneWave-AI/claude-skills --skill spreadsheet-model-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spreadsheet-model-auditor, .gemini/skills/spreadsheet-model-auditor, .github/skills/spreadsheet-model-auditor and .opencode/skills/spreadsheet-model-auditor in your project.

What does Spreadsheet Model Auditor need to run?

Going by SKILL.md and its folder, Spreadsheet Model Auditor needs Python for the scripts in its folder and the command-line tools its instructions call (soffice, python3 and pip). Our summary lists: Python 3.

Does Spreadsheet Model Auditor access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Spreadsheet Model Auditor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Spreadsheet Model Auditor use?

Spreadsheet Model Auditor is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Spreadsheet Model Auditor use?

About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.1k tokens, read only when the agent opens those files.

What are the alternatives to Spreadsheet Model Auditor?

Skills that share tags, products or a category with Spreadsheet Model Auditor: XLSX Spreadsheet Toolkit (XiaomiMiMo/MiMo-Code, 14k stars), XLSX (NousResearch/hermes-agent, 252k stars), Excel Spreadsheet Builder (agentscope-ai/QwenPaw, 36k stars) and XLSX (jjyaoao/HelloAgents, 3.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Spreadsheet Model Auditor?

OneWave-AI (a GitHub organization) maintains it in OneWave-AI/claude-skills, which has 328 GitHub stars. The repository holds 69 skills in this directory. The repository was last updated on October 2, 2026.

Source: OneWave-AI/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.