Back to skill

Security audit

Automate Excel 0.1.3

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local Excel automation skill, with normal spreadsheet file risks around overwrites, formulas, and dependency hygiene.

Install only in an environment where you are comfortable processing the selected spreadsheets. Use separate output paths or backups for important workbooks, avoid converting untrusted CSV/template data unless formula-like values are neutralized, and consider pinning dependencies before production use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/csv_to_excel.py:35
Finding

Spreadsheet Formula Injection in CSV-to-Excel Conversion

Content
View full analysis
31: sheet_name = sheet_name[:31] df.to_excel(out, sheet_name=sheet_name, index=False, engine="openpyxl") print(f"Converted {len(df)} rows -> {out} (sheet: {sheet_name})") return paths = [Path(p) for p in args.inputs] for p in paths: if not p.exists(): print(f"File does not exist: {p}", file=sys.stderr) sys.exit(1) with pd.ExcelWriter(out, engine="openpyxl") as writer: for path in paths: df = pd.read_csv(path, encoding=args.encoding, sep=args.sep) name = path.stem if len(name) > 31: name = name[:31] df.to_excel(writer, sheet_name=name, index=False) ``` ### Technical Analysis CSV values are transferred directly into an XLSX workbook without checking whether string values begin with spreadsheet formula metacharacters. In particular, a value beginning with `=` can be stored as an active formula by the Excel-writing engine. Values beginning with `+`, `-`, or `@` should also be treated as potentially dangerous for compatibility with spreadsheet clients and downstream conversions. The input file is therefore treated as trusted executable spreadsheet content rather than untrusted data. An attacker who controls a CSV cell can introduce formulas containing hyperlinks, external workbook references, web-service calls, or other client-supported formula features. ### Attack Path 1. An attacker supplies a CSV file containing a crafted value, such as an external-reference or hyperlink formula ...[truncated 1320 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/template_fill.py:17
Finding

Spreadsheet Formula Injection Through Template Placeholder Substitution

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unbounded Third-Party Dependency Versions

Content
View full analysis
=3.1.0 pandas>=2.0.0 xlrd>=2.0.0 ``` The same dependency declarations appear in both requirements files. ### Technical Analysis The manifests specify only minimum versions and do not impose upper bounds, exact versions, lock-file resolution, or package integrity hashes. As a result, installing the Skill at different times can retrieve different dependency versions. The listed names correspond to established PyPI projects, and the audit found no typosquatted dependency, custom package source, or currently embedded malicious package. Nevertheless, unbounded resolution weakens build reproducibility and can automatically introduce a future compromised, vulnerable, or behaviorally incompatible release. ### Attack Path 1. A user follows the documented installation command using one of the requirements files. 2. The package resolver selects the newest releases satisfying the minimum-version constraints. 3. A selected release contains a newly introduced vulnerability, malicious modification, or incompatible behavior. 4. The package is installed into the user's Python environment. 5. Its code runs when imported or when spreadsheet processing functions are invoked. This path depends on a future upstream compromise or vulnerable release; no current malicious dependency was identified during the audit. ### Impact Assessment Any resulting impact would occur with the privileges of the user or service installing and running the Skill. Depending on the nature of an affected upstream package, the potential scope could include: - Access to spreadsheet data processed by the Skill. - File access available to the Python process. - Arbitrary code execution if an upstream package were compromised. - Availability or integrity failu ...[truncated 179 chars]
Remediation
View remediation
--hash=sha256: pandas== --hash=sha256: xlrd== --hash=sha256: ``` ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (26)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly demonstrates writing and overwriting spreadsheet and CSV outputs, including saving back to an existing file, without consistently requiring backups, confirmation, or safer output naming. In a file-manipulation skill, this can lead to unintended data loss or corruption if users or downstream agents reuse input paths or overwrite important workbooks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file documents several scripts where --output is optional and the default behavior is to overwrite the input workbook (默认覆盖), but it does not include any caution about data loss or recommend backups. Because markdown files should warn about behaviors that can affect user data or system integrity, these destructive defaults need explicit disclosure.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/_make_test_data.py (reported line 50)May include surrounding context.

python
df_main.to_csv("sample.csv", index=False, encoding="utf-8-sig")

# 模板:第一行表头,第二行占位符 {{姓名}} {{金额}}
wb_tpl = __import__("openpyxl").Workbook()
ws = wb_tpl.active
ws["A1"], ws["B1"], ws["C1"] = "姓名", "金额", "地区"
ws["A2"], ws["B2"], ws["C2"] = "{{姓名}}", "{{金额}}", "{{地区}}"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The docstring and user-facing argument descriptions are entirely in Chinese, which imposes a specific language on users without offering a choice or documenting that the tool is intended only for a Chinese-language audience. This matches the language/locale policy concern for natural-language content in code files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The docstring and CLI help text are entirely in Chinese, which imposes a specific language on users without any opt-in or indication that the tool is intentionally region-specific. Under the policy, language constraints should either be user-selectable or clearly justified as locale-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring and CLI description are entirely in Chinese, which imposes a specific language on users. The file provides no opt-in, alternative locale, or explanation that the tool is intended only for a Chinese-speaking or region-specific environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and command descriptions are written entirely in Chinese, and the CLI description/help text also uses only Chinese. This imposes a language choice on users without opt-in or an alternative locale, which matches the policy concern for language/locale restrictions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The primary instructional content and title are presented in Chinese, and the activation guidance also assumes Chinese-language use, with no indication that other languages are supported or that Chinese is an intentional locale restriction. This can constitute a language/locale policy issue when no user opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language instructions, labels, and examples are entirely in Chinese, including column names and usage descriptions, with no indication that the skill supports other languages or that Chinese is a justified locale-specific requirement. This can violate language/locale policy when a specific language is imposed without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains numerous examples that write new Excel or CSV files, such as to_excel, to_csv, and commands with --output or --output-dir, but it does not include any warning about file creation, overwriting risks, or the need to verify output paths. For markdown files, the skill description should warn about behaviors that could affect user data or system integrity.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency is specified with a lower-bound only (openpyxl>=3.1.0), which makes builds non-reproducible and allows future installs to pull in unexpected versions, including buggy or compromised releases. In a skill that parses spreadsheet files, dependency behavior directly affects file-handling safety, so lack of pinning modestly increases supply-chain and stability risk.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
openpyxl>=3.1.0
pandas>=2.0.0
xlrd>=2.0.0

Unverifiable Dependency: openpyxl has 2 known advisory(ies) (CVE-2017-5992 (Improper Restriction of XML External Entity Reference in Openpyxl); CVE-2017-5992 (Openpyxl 2.4.1 resolves external entities by default, which allows remote attack)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
87% confidence
Finding

The manifest does not pin openpyxl, so it is impossible to verify from this file alone whether deployment will use a version affected by known advisories, including historical XXE issues. Because this skill processes Excel files, any XML parsing weakness in the workbook stack is more relevant than it would be in an unrelated skill.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

pandas>=2.0.0 is unpinned, so installations may resolve to different versions over time. This creates supply-chain uncertainty and can introduce vulnerable or incompatible releases into a data-processing skill that handles user-supplied spreadsheet content.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
openpyxl>=3.1.0
pandas>=2.0.0
xlrd>=2.0.0

Unverifiable Dependency: pandas has 1 known advisory(ies) (CVE-2020-13091 (** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
79% confidence
Finding

Because pandas is unpinned, the file does not establish whether an affected or unaffected release will be installed relative to known advisories. In a spreadsheet/data-import skill, deserialization and parsing libraries deserve extra scrutiny because they may process attacker-controlled files or content.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

xlrd>=2.0.0 allows any later version, reducing build reproducibility and making it harder to verify which code will run in production. For a spreadsheet automation skill, parser-library changes can affect security posture and file handling in subtle ways.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
openpyxl>=3.1.0
pandas>=2.0.0
xlrd>=2.0.0

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring and argparse help strings are entirely in Chinese, which imposes a specific language on users. The policy allows fixed locale only when user choice is offered or the regional constraint is clearly justified, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file's user-facing natural-language description and usage text are entirely in Chinese, which implies a fixed language/locale choice. The policy requires flagging language or locale constraints when they are imposed without user opt-in or an explicitly documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring presents the skill description, condition syntax, and usage examples entirely in Chinese, with no indication that users may choose another language or that the tool is intended only for a Chinese-speaking or region-specific context. This creates a natural-language locale policy concern because the skill implicitly requires a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python file contains natural-language docstrings, argument help text, and output messages entirely in Chinese. Under the policy rule, forcing a specific language without opt-in is a locale-policy issue unless the regional constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency is specified with a lower-bound range rather than an exact version, which makes builds non-reproducible and can pull in different releases over time. In a skill that processes untrusted spreadsheet files, dependency drift increases supply-chain risk and makes it harder to verify whether known vulnerable versions are being installed.

Content

Scanner excerpt · scripts/requirements.txt (reported line 1)May include surrounding context.

text
openpyxl>=3.1.0
pandas>=2.0.0
xlrd>=2.0.0

Unverifiable Dependency: openpyxl has 2 known advisory(ies) (CVE-2017-5992 (Improper Restriction of XML External Entity Reference in Openpyxl); CVE-2017-5992 (Openpyxl 2.4.1 resolves external entities by default, which allows remote attack)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

openpyxl has historical advisories, including XXE-related issues, and because the manifest does not pin a version there is no assurance that deployment will avoid affected releases. In an Excel-automation skill that may ingest externally supplied workbooks, uncertainty around parser versioning increases risk because vulnerable XML handling could be exposed by malicious files.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

Using an unpinned pandas version allows package resolution to select different releases across environments or over time, reducing reproducibility and weakening supply-chain control. Because this skill is intended for spreadsheet/data processing, dependency predictability matters for both security review and safe handling of potentially untrusted input files.

Content

Scanner excerpt · scripts/requirements.txt (reported line 2)May include surrounding context.

text
openpyxl>=3.1.0
pandas>=2.0.0
xlrd>=2.0.0

Unverifiable Dependency: pandas has 1 known advisory(ies) (CVE-2020-13091 (** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
85% confidence
Finding

pandas has a cited historical advisory, and without an exact version pin it is impossible to verify from this manifest alone whether an affected release could be installed. While the referenced issue may depend on unsafe deserialization usage elsewhere, the unpinned dependency still leaves security posture unverifiable and therefore weakens trust in deployments.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The xlrd requirement is not pinned to a single version, so future installations may resolve to different package contents than were originally reviewed. This creates a low-severity supply-chain and reproducibility issue, especially in a file-processing skill where libraries parse external spreadsheet content.

Content

Scanner excerpt · scripts/requirements.txt (reported line 3)May include surrounding context.

text
openpyxl>=3.1.0
pandas>=2.0.0
xlrd>=2.0.0

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file’s user-facing natural-language documentation is entirely in Chinese, including the description and usage instructions. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation, and this file does not indicate that the tool is intentionally region-specific or offer an alternative language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.