Back to skill

Security audit

Sheet Agent

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent spreadsheet helper that reads and may modify user-selected CSV/Excel files after preview and confirmation, with ordinary dependency and input-validation cautions.

Install only in an environment where you are comfortable granting access to the spreadsheets you name. Review previews carefully before confirming edits, remember that backups may contain spreadsheet data, and prefer pinned dependency installation if you maintain this skill.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:7
Finding

Unpinned Third-Party Dependencies Create Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
openpyxl== ``` 2. Generate and commit a fully resolved lock file that includes transitive dependencies. 3. Use hash verification, such as pip's `--require-hashes`, with reviewed distribution hashes. 4. Install only from the official Python Package Index or a controlled internal mirror: ```bash python -m pip install --index-url https://pypi.org/simple --require-hashes -r requirements.txt ``` 5. Regularly scan locked dependencies for published vulnerabilities and update them through a reviewed process. 6. Replace both unpinned installation instructions with the locked, hash-verified installation command. 7. Avoid installing dependencies with administrative or root privileges. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
scripts/sheet_agent.py:427
Finding

User-Controlled Input Is Evaluated as a Regular Expression

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill describes file modification behavior, including confirmed writes and automatic backups, but does not declare any explicit tool scope or permissions boundary. Without an allowlist such as permissions or allowed-tools, an agent/runtime may grant broader filesystem capabilities than intended, increasing the risk of unintended or unsafe file writes if the skill is invoked on attacker-influenced paths or ambiguous confirmation flows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The script hard-codes mixed English and Chinese trigger vocabularies, including confirmation and cancellation words, which creates an implicit language policy in the skill's natural-language interface. There is no visible opt-in, language selection mechanism, or documented justification that the skill is intended only for a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This manifest explicitly declares write access to spreadsheet files, which can affect user data integrity. The summary and description mention "preview edits safely," but they do not clearly warn that the skill can write or modify CSV/Excel files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.