Back to skill

Security audit

Excel自动化脚本生成器

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Chinese-language Excel automation prompt skill that generates user-requested code and does not install, execute, persist, or access data by itself.

Before installing, understand that the skill is only a code/formula generator. Review generated code, test it on sample files, and back up Excel or CSV data before running anything against business, finance, attendance, or payroll records.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly promises to generate runnable Python and Excel automation code, but it does not warn users that executing the generated output may modify local files, spreadsheets, or business data. In this context, omission of an execution-safety warning increases the risk that users will run destructive or irreversible code against production documents without appropriate review or backups.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

All user-facing instructions in the skill are written as Chinese-only guidance, and the skill does not indicate that users may choose another language or that the Chinese-only scope is intentional for a specific region or compliance need. This can constitute a language/locale policy issue under the natural-language policy rule.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.