Spreadsheet & Data Wrangling Master

Security checks across malware telemetry and agentic risk

Overview

This is a text-only spreadsheet helper whose broad prompts and file-output examples need user awareness but fit its stated data-cleaning purpose.

Install this if you want spreadsheet and data-wrangling help. Invoke it intentionally for CSV, Excel, Google Sheets, or other tabular data; review any generated cleaned files, reports, or automation steps before using or sharing them, especially when the data includes private customer, financial, or business information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The README defines very generic activation phrases like 'Analyze this data' and 'Build a dashboard' that are likely to appear in ordinary user requests. In an agent ecosystem where skills may auto-trigger from natural language, this broad matching can cause unintended invocation of the skill, leading to context hijacking, incorrect tool selection, or processing of sensitive tabular data when the user did not explicitly choose this capability.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill defines highly generic natural-language triggers such as "Clean this CSV", "Analyze this data", and "Build a dashboard," which closely match common user requests across many contexts. This can cause unintended activation or routing to this skill when a user did not explicitly request it, leading to inappropriate handling of data, accidental file processing, or bypass of a more appropriate specialized workflow.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal