Back to skill

Security audit

CSV Wizard

Security checks for vulnerabilities and agentic risk

Overview

This is a small CSV-cleaning skill whose documented data changes are explicit and purpose-aligned, with no packaged executable or hidden privileged behavior found.

Install only if you are comfortable with a Chinese-language CSV-cleaning workflow. Use copies of important datasets and review previews or outputs before relying on options that drop rows, fill missing values, deduplicate, or standardize names. Note that the inspected package declares a CLI entrypoint but does not include the referenced executable, so functionality may be incomplete unless supplied elsewhere by the installer.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README documents destructive cleaning operations such as dropping rows with missing values and deleting duplicates, but it does not warn users about irreversible data loss or recommend reviewing output and keeping backups. In a data-cleaning CLI, users may run commands directly against important datasets and silently lose records, especially when following copy-paste examples from documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description, command descriptions, and all user-facing documentation are written only in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. The policy requires flagging language or locale constraints when they are imposed without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents data-modifying behaviors such as dropping duplicate rows and writing cleaned output files, but it does not include any user-facing warning about reviewing transformations before saving or the risk of data loss from destructive cleaning choices. For markdown files, safety-relevant effects on user data should be disclosed clearly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest’s user-facing description, option help, and command descriptions are entirely in Chinese, which imposes a specific language on users. Under the policy, locale or language constraints should either offer user choice or be clearly documented as justified for a region-specific tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The primary descriptive text for the skill is presented in Chinese, while the rest of the README includes English headings and commands, and there is no indication that the skill is intentionally region-specific or that users can choose their preferred language. This can violate language/locale policy when a specific language is imposed without opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.