Back to skill

Security audit

Excel Spreadsheet

Security checks across malware telemetry and agentic risk

Overview

This spreadsheet-generation skill is purpose-aligned and uses an openly named CellCog integration, but users should treat prompts and spreadsheet data as potentially sent to CellCog.

Install this only if you are comfortable using CellCog as an external spreadsheet-generation service. Avoid sending confidential, regulated, employee, customer, or financial data unless your organization has approved CellCog's privacy, retention, and security terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill advertises spreadsheet generation for budgets, financial models, employee directories, sales trackers, and similar use cases, but it does not clearly disclose that user-supplied data may be transmitted to the third-party CellCog service. This creates a real privacy and data-governance risk because users may provide sensitive financial, personnel, or business data under the assumption the processing is local or without understanding the external data flow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.