Back to skill

Security audit

exceldashboard-report

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent ExcelDashboard AI report helper, but users should understand that report outlines and aggregated business data are sent to an external service and become accessible through generated report links.

Install this only if you are comfortable sending analyzed report outlines, metrics, chart data, and related source context to ExcelDashboard AI. Avoid using it with confidential, regulated, or customer-identifying data unless your organization approves that service and its generated read-only report links.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description says to use the skill when users request an ExcelDashboard AI report from several inputs or 'ask to track an existing report job,' but it does not define narrow trigger phrases or exclusion conditions. This broad natural-language invocation guidance could cause the skill to activate on ordinary report-related requests without clear boundaries for when another skill or normal assistance should be used instead.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This skill instructs the agent to use local file-reading and analysis capabilities, then send the resulting outline and derived business content to an external service at exceldashboard.ai for report generation. That creates a real data exfiltration boundary: sensitive information from uploaded files, computed metrics, or research content may be transmitted to a third party, and the skill also notes that a public read-only share is automatically created on completion.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
Use the current client's file-reading, computation, and web-search capabilities to complete the analysis. ExcelDashboard AI generates reports from the resulting outline. This Skill orchestrates only two MCP tools: `create_report` and `get_report`.

The official connection guide is https://www.exceldashboard.ai/mcp and the Streamable HTTP endpoint is https://api.exceldashboard.ai/mcp. Installing these instructions does not configure MCP or complete browser OAuth. Discover the two tools on the authorized ExcelDashboard AI connection before calling them; reading documentation is not proof of connection.

These instructions are written in English. User-facing replies and report content should follow the user's requested language; the instruction language does not require English report content.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
## Creation and Tracking

1. Use the workspace selected on the OAuth consent page for the current connection. Tool calls do not require `workspace_id`. If the connection is unauthorized, ask the user to connect ExcelDashboard AI in the client and select a workspace. Switching workspaces requires authorization again. Do not ask users to send tokens or workspace IDs in the conversation.
2. Call `create_report` with the complete `outline` and, when needed, `locale` (default: `zh-CN`). Each call submits a new job; do not automatically retry creation. Save the returned `job_id` and immediately show the returned `report_url` as a "View report" link. If a callable built-in browser tool is available, open this URL before the first `get_report` call and save the tab identifier; do not wait until completion to open it. If no such tool exists or opening fails, explain this and continue tracking the job. ExcelDashboard AI automatically creates a public read-only share when generation completes; users do not need to share manually in the frontend. The preview's Edit button separately verifies the signed-in account and editing permissions.
3. Query status with `get_report({"job_id":"..."})`. Within the client's available execution time, poll serially using the returned `poll_after_seconds`, or approximately 15 seconds if absent. Do not query the same job concurrently. Report actual progress using `stage`, `completed_pages`, `pages_started`, and `total_pages`; do not invent percentages. After every `get_report` result, update the user-visible progress and refresh the same built-in browser tab, keeping the returned preview link in the update. If the client cannot keep waiting, give the user the `job_id` and preview link. The page updates its own progress; resume by querying the existing job next time rather than creating the same report again.
4. Check `status` and `report_url` after each `get_report` result. When `status` is `completed`, stop polling immediately, present the link 
...[truncated 25 chars]

Static analysis

No suspicious patterns detected.