Excel

Security checks across malware telemetry and agentic risk

Overview

This is a spreadsheet-help skill that gives formulas, pivot guidance, and optional VBA advice, with no evidence of hidden execution or data theft.

Reasonable to install for spreadsheet help. Treat any generated VBA as executable code: review file paths, ranges, and workbook changes, keep backups, and only run macros you understand and explicitly choose to execute.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are very broad and map to common, everyday spreadsheet requests such as writing formulas, cleaning data, or building pivot tables. This increases the chance of unintended invocation, causing the skill to activate in contexts where a user did not explicitly request this specific skill, which can lead to incorrect tool selection, unexpected behavior, or prompt-routing abuse in multi-skill environments.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal