Back to skill

Security audit

Excel Data Quality Check

Security checks for vulnerabilities and agentic risk

Overview

This spreadsheet helper mostly does what it says, but its local-only claims conflict with an external ChartGen workflow and its chart commands can create files or follow external skill instructions with weak safeguards.

Install only if you are comfortable reviewing the workflow before use. Treat core quality checks and basic charts as local spreadsheet processing, but do not use Advanced Chart unless you explicitly trust ChartGen, its API, and the exact installed version. Avoid sensitive spreadsheets unless output previews are acceptable, and ensure chart outputs are written only to a controlled directory.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
--config '<json>' ``` ``` ### Technical Analysis The workflow instructs the Agent to construct shell commands by substituting file paths, output paths, and generated JSON directly into command templates. The file and output path placeholders are not quoted. Although the JSON placeholder is surrounded by single quotes, user-controlled values such as chart titles can contain a single quote and terminate that quoting context. If the Agent executes these templates through a shell, shell metacharacters in a c ...[truncated 1488 chars]:106
Finding

Shell Command Injection Through Unquoted File Paths and JSON Arguments

Content
View full analysis
``` ``` ```markdown ### Inspect data (planning only) ```bash node tools/chart_renderer.js --info ``` ### Render a chart ```bash node tools/chart_renderer.js --config '' [--output ] ``` ``` ```markdown ### Step 2 — Render Charts **Immediately render all planned charts** — do NOT ask for confirmation first. For each chart, call the tool: ```bash node tools/chart_renderer.js --config '' ``` ``` ### Technical Analysis The workflow instructs the Agent to construct shell commands by substituting file paths, output paths, and generated JSON directly into command templates. The file and output path placeholders are not quoted. Although the JSON placeholder is surrounded by single quotes, user-controlled values such as chart titles can contain a single quote and terminate that quoting context. If the Agent executes these templates through a shell, shell metacharacters in a crafted filename, output path, or chart configuration can be interpreted as command separators, substitutions, or redirections rather than literal argument content. The JavaScript CLI itself does not invoke a shell, but the documented Agent workflow creates the vulnerable command-construction boundary. ### Attack Path 1. An attacker supplies a spreadsheet with a filename containing shell metacharacters, or requests a chart title/output path containing a quote followed by shell syntax. 2. The Agent substitutes that value into one of the documented command templates. 3. The resulting command is passed to a shell-based execution tool. 4. The crafted value breaks out of its intended argument context. 5. The she ...[truncated 652 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
tools/chart_renderer.js:268
Finding

Unrestricted Output Path Allows Arbitrary Writable-File Overwrite

Content
View full analysis
'\n"); process.exit(1); } const config = JSON.parse(configStr); const option = buildOption(config, headers, rows); if (!outputPath) { const dir = path.dirname(filePath); const base = path.basename(filePath, path.extname(filePath)); const suffix = config.title ? config.title.replace(/[^a-zA-Z0-9\u4e00-\u9fff]/g, "_").slice(0, 30) : config.type || "chart"; outputPath = path.join(dir, `${base}_${suffix}.png`); } const absOut = path.resolve(outputPath); await renderToPng(option, config.width, config.height, absOut); ``` ### Technical Analysis The `--output` argument accepts any path. The program resolves that path to an absolute location and passes it directly to Sharp's `toFile` operation. It does not enforce a dedicated artifact directory, require a `.png` extension, reject traversal, check for symbolic links, or prevent replacement of an existing file. Consequently, any caller able to influence `--output` can direct PNG bytes to an arbitrary writable filesyst ...[truncated 1160 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
tools/lib/parser.js:14
Finding

Unbounded Spreadsheet Parsing and Image Dimensions Permit Resource Exhaustion

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/advanced-chart.md:13
Finding

Unpinned External Skill Installation and Blind Delegation Create a Supply-Chain Boundary

Content
View full analysis
The advanced chart capability requires **ChartGen AI** which is not currently installed. > > **Options:** > 1. **Install ChartGen**: Tell me "install skill https://github.com/chartgen-ai/chartgen-skill.git" > 2. **Use basic charts**: I can create bar, line, pie, scatter, and area charts locally (no API needed) > 3. **Export data**: I can clean and export your data for use in other visualization tools ``` ### Technical Analysis The advanced-chart workflow instructs the Agent to locate a sibling Skill and follow its instructions, or install that Skill from a mutable Git repository URL. No commit hash, release version, checksum, signature, or review gate is specified. This creates two trust problems: 1. A locally replaced `../chartgen-skill/SKILL.md` can supply arbitrary new Agent instructions. 2. The remote repository's effective ...[truncated 1528 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description emphasizes a comprehensive data-quality diagnosis system with many scan modules, scoring, semantic/agent analysis, and proactive activation on CSV/XLS/XLSX/TSV mentions. This code chunk instead implements a CLI utility that parses a file, reports simple schema/statistics information, constructs ECharts option objects for common chart types, and renders them to PNG files. While there is partial overlap in that it works on tabular files and uses ECharts for visualization, the primary purpose is materially narrower and different: chart generation plus basic column profiling, not full data-quality diagnosis. The claimed automatic trigger/menu behavior is also absent from the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code implements a narrow local data profiling CLI: it reads a provided file path, parses the file, computes a profile, and prints JSON. This partially aligns with the description's data quality diagnosis theme for CSV/Excel-like files, but the declared description claims substantially broader functionality that is not represented here, especially interactive chart generation via ECharts, agent-powered semantic analysis, automatic trigger/menu behavior, and specific multi-module/scoring features. Because the code's actual behavior is materially narrower than the declared primary capability set, this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description promises a rich data-quality and visualization skill, but the supplied code chunk only performs basic spreadsheet/tabular file parsing and JSON output. Its primary purpose is extracting headers, counts, parse metadata, and a preview from a file path. None of the headline capabilities in the description—diagnostic scans, scoring, semantic analysis, or chart generation—appear in this code. This is a material description-to-behavior mismatch rather than a mere partial implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The supplied code is a parser utility, not a full data-quality diagnosis and visualization skill as described. It supports the declared file types and operates locally, which is consistent with part of the description, but the primary declared purpose is materially broader: diagnostics, scoring, semantic analysis, interactive charts, and activation behavior. None of those higher-level capabilities appear in this code chunk. The code’s actual behavior is limited to ingesting tabular files and returning normalized rows plus parse metadata and warnings. This is a substantial description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The supplied code chunk is narrowly focused on profiling already-parsed tabular data in memory. It analyzes rows and columns, infers types, computes null/duplicate statistics, detects patterns like emails/phones/dates/currencies, and returns validity warnings. This is consistent with part of a data quality diagnosis feature, but it does not implement several major elements emphasized in the description: interactive charts/ECharts, semantic agent analysis, extensive multi-module scanning, explicit spreadsheet activation behavior, or file/menu trigger logic. Because those are core claimed capabilities rather than minor omissions, the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The supplied code is strongly aligned with the 'Excel/CSV data quality diagnosis' portion of the description: it contains 20+ scan modules and checks many quality dimensions (completeness, uniqueness, consistency, validity, accuracy, timeliness). However, the declaration includes several major capabilities not supported by this code chunk: semantic/agent analysis, ECharts/interactive chart generation, and trigger/UI behavior for file mentions/uploads. The code is a scanner library only, returning modules and issues; it does not render charts, manage interaction menus, or implement agentic reasoning. Because these are material advertised capabilities rather than minor supporting details, the description overstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The supplied code chunk is narrowly a scorer module. It supports part of the declared description: 6-dimension scoring for data-quality issues and local execution. However, it does not show file handling for CSV/XLS/XLSX/TSV, scan modules, interactive/ECharts chart generation, semantic/agent analysis, or trigger/menu behavior. Because the description presents a much broader end-user capability set than this code actually implements, the description is not accurately represented by this code chunk alone.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a comprehensive spreadsheet data-quality and visualization skill that should detect uploaded tabular files, analyze them, score them, and render charts. The supplied code does not implement those primary capabilities. Instead, it contains only low-level utility helpers such as statistical calculations and date/number parsing, which could support a data analysis tool but do not by themselves realize the declared behavior. There is no evidence of file ingestion, Excel/CSV-specific processing, interactive charts, semantic analysis, trigger activation, or UI/menu behavior. This is therefore a clear description-to-code mismatch rather than merely supporting implementation detail, because the chunk’s observable functionality is much narrower and materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The implemented code does match part of the description: it performs local tabular data quality scanning, profiling, issue detection, and scoring. However, several prominent declared capabilities are not represented in the supplied code chunk. There is no chart rendering or ECharts integration, no interactive UI/menu behavior, and no evidence of agent-powered semantic analysis. The code is a command-line JSON emitter, not an interactive visualization skill. Also, while the description specifically highlights Excel/CSV file types, this chunk only shows generic file parsing via parseFile and does not itself demonstrate those format-specific triggers or activation behavior. Therefore the description materially overstates and misrepresents the actual behavior shown.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The activation condition is overly broad because it triggers on any mention of supported file types, even without an explicit request. In a skill that deals with local files and file-derived context, this can lead to unsolicited processing prompts, accidental disclosure of file-related context, and erosion of user consent boundaries.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README makes a strong trust claim that the skill is 'fully local' and needs 'no external services,' but later documents an advanced-chart path that delegates to ChartGen and requires an API key. This mismatch can mislead users and agents into enabling or invoking capabilities under false privacy and connectivity assumptions, especially when handling sensitive spreadsheet data.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The requirements section states 'No API keys, no external services, no internet required,' which directly conflicts with the documented advanced-chart delegation to ChartGen. In a security-sensitive skill ecosystem, inaccurate dependency and network claims can cause unintended data disclosure or policy violations if users assume all processing remains offline.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documented usage model and metadata encourage activation whenever a user uploads or merely mentions common spreadsheet file types, even without an explicit request. Overly broad triggering increases the chance the skill will process sensitive files or preempt user intent, which is risky for a tool that inspects data contents and may invoke charting or other follow-on actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Presenting a skill menu immediately on any file mention, despite rules requiring explicit choice per file, creates a consent and routing weakness. In an agent environment handling user files, conflicting instructions can lead to unrequested engagement with potentially sensitive documents and unpredictable downstream behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Presenting a skill menu immediately on any file mention, despite rules requiring explicit choice per file, creates a consent and routing weakness. In an agent environment handling user files, conflicting instructions can lead to unrequested engagement with potentially sensitive documents and unpredictable downstream behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The sub-skill explicitly delegates work to an external ChartGen API despite the parent skill being described as 'Fully local.' This creates a trust-boundary and transparency problem: users may provide spreadsheet data expecting local-only processing, but advanced-chart requests could cause data to be sent to a third party, exposing potentially sensitive business or personal data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instructions encourage installing and using an external API-backed skill that is outside the stated local Excel/CSV analysis scope, increasing supply-chain and data-exfiltration risk. Because the parent skill is triggered whenever users upload spreadsheet files, this context makes the issue more dangerous: users may be funneled from routine data analysis into a third-party integration without appreciating the privacy and security implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to immediately render charts and create PNG files without first obtaining user confirmation or warning that local files will be generated. In a file-handling skill that auto-activates on spreadsheet upload, this weakens user control over side effects and can cause unexpected processing or artifact creation from potentially sensitive data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs the agent to translate or localize field display names into the user's language without first confirming that the uploaded dataset is safe to transform or that the user wants translation. This can alter raw labels, obscure original source terminology, and create privacy or integrity risks when users expect faithful reporting of uploaded spreadsheet contents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The profiler returns per-field sampleValues and, for low-cardinality columns, topValues derived directly from user-uploaded spreadsheet contents. In a skill that auto-activates on CSV/XLS(X)/TSV upload and performs data profiling, this can expose emails, IDs, phone numbers, financial values, or other sensitive business records to downstream UI, logs, or other components without minimization or explicit user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

extractSample selects the most complete rows and returns whole records with every header value serialized, which can disclose entire user records rather than aggregate statistics. In this skill context, uploaded spreadsheets commonly contain customer, employee, financial, or operational data, so automatic sampling materially increases privacy and data-leak risk even if processing is local.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file embeds fixed language-specific keyword lists for Chinese, Japanese, Korean, Spanish, French, German, Arabic, and others to infer semantics such as primary keys, dates, phones, totals, and ID formats. This imposes locale behavior implicitly in the scanner logic rather than offering a user-selected locale or clearly documented regional mode, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a local spreadsheet/CSV data quality diagnosis and visualization skill. While generic quality checks are in scope, implementing checksum validation for Chinese ID-card numbers adds a sensitive identity-document validation capability that is not clearly necessary for the stated purpose and goes beyond ordinary spreadsheet diagnostics.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comments and logic state that ambiguous dates like 01/02/2024 are parsed using a fixed MM/DD/YYYY default 'for compatibility'. This imposes a specific locale interpretation in natural-language comments and behavior without offering a user choice or documenting an explicit regional constraint, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The instruction requires titles and axis labels to always be set in the user's language, which is a language-policy decision embedded in natural language. Because the skill does not explicitly offer language/locale choice or opt-in, this may violate the policy requirement against forcing a language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.