Back to skill

Security audit

excel去重清洗

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a straightforward spreadsheet cleanup helper that creates a cleaned copy and does not show hidden network, credential, persistence, or destructive behavior.

Before installing, be aware that the skill can remove duplicate rows and normalize contact/identity-like fields in the output workbook. Confirm the intended key columns and review the generated report, especially for sensitive customer, roster, or registration data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger conditions are broad enough that the skill may activate on generic spreadsheet-handling requests beyond narrowly intended deduplication/cleaning tasks. In an agent setting, overbroad routing can cause the wrong skill to process sensitive user files, leading to unintended modification, privacy exposure within the toolchain, or unsafe handling assumptions.

Vague Triggers

Medium
Confidence
86% confidence
Finding
Ambiguous trigger words like '去重', '清洗', and '数据标准化' lack scope boundaries, so the skill could be selected for many ordinary data workflows where destructive cleaning or deduplication is not desired. Because this skill operates on uploaded files and may alter records or remove duplicates, mistaken activation can affect data integrity and confidentiality expectations.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.