Back to skill

Security audit

Excel XLSX Formula Cleanup

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Excel workbook repair helper with some broad trigger wording but no hidden code execution, credential use, persistence, or exfiltration behavior.

Reasonable to install for Excel workbook repair tasks. Because it can be invoked implicitly and deals with potentially important spreadsheets, review before applying edits, work on copies, and be especially careful with .xlsm files, external links, Power Query connections, and business-critical formulas.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad, generic, and written in a way that can match ordinary Excel help requests rather than a narrowly scoped skill invocation. This increases the chance of accidental activation, causing the agent to apply workbook-modifying workflows in situations where the user did not explicitly intend to use this skill, which can lead to unintended file handling or risky automation steps.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger sentence is broad enough to overlap with ordinary user phrasing, which can cause the skill to activate in contexts where the user did not explicitly intend to invoke it. In an agent environment, this increases the risk of prompt-scope confusion, unintended tool routing, and accidental handling of sensitive Excel workbooks or macro-bearing files under the wrong workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger sentences are malformed, generic, and broad enough to create ambiguous activation conditions for the skill. In an agent system, unclear triggers can cause the skill to be invoked for unintended Excel- or data-related requests, increasing the chance of inappropriate file handling, workbook modification, or preservation of risky content such as macros without the user explicitly asking for it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This file is presented as a Chinese README, but key user-facing descriptive content is written in English rather than offering a language choice or clearly documenting the reason for the locale mismatch. That can violate language/locale expectations for a localized skill document.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

A central behavior description in the Chinese README is written in English, which forces a different language in a localized document without user opt-in. This creates an avoidable language-policy inconsistency in the skill's natural-language documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger examples presented to users in this Chinese-language file are entirely in English and do not provide a Chinese alternative or language choice. For a localized user guide, that imposes a language constraint without opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description activates on a very broad set of user situations and keywords around Excel help, without enough scoping constraints to distinguish genuine workbook-repair tasks from ordinary conversation about spreadsheets. In an agent environment, this can cause unintended skill invocation, pulling the model into file-handling or automation guidance when the user did not explicitly request this specialized behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The listed trigger keywords are generic terms like 'xlsx', 'formula', 'power query', and 'vba', which commonly appear in normal technical discussion and therefore create a high chance of accidental activation. Overbroad keyword triggers increase prompt-routing risk, making the agent apply this skill outside its intended scope and potentially mishandle user intent or sensitive spreadsheet workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example trigger phrases use broad, natural-language help requests that resemble everyday user prompts, so they are likely to collide with routine conversation rather than uniquely identify this skill's niche use case. This makes misrouting more likely, especially because the skill covers workbook automation and preservation tasks that may affect files, formulas, and macros if applied unnecessarily.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill's display and default prompt describe a very broad set of Excel repair and automation tasks without stating safety boundaries, required user confirmation, or file-handling constraints. Because implicit invocation is supported elsewhere in the file, this broad wording can cause the agent to select the skill for generic workbook requests and perform high-impact workbook modifications on sensitive files without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Enabling allow_implicit_invocation without concrete trigger restrictions allows the agent to invoke this skill automatically for loosely related Excel tasks. In the context of a skill that can inspect and fix formulas, named ranges, pivots, Power Query, and macro-preserving workbooks, unintended invocation could lead to unauthorized file access, destructive edits, or modification of business-critical spreadsheet logic.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation guidance does not define clear boundaries for when the skill should or should not run, making it easier for the agent to over-apply the skill based on weak semantic matches. This can lead to misrouting, unnecessary file inspection, or accidental application to incompatible spreadsheet tasks, especially where workbooks may contain sensitive business logic or VBA.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
67% confidence
Finding

The file lists separate English and Chinese instruction and README files, but does not explain how the user's preferred language is selected. Without an explicit opt-in or language-selection rule, the skill packaging may imply locale behavior that is not clearly user-driven.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The file includes Chinese-language evidence links and titles, but it does not state whether the skill may operate in Chinese, English, or another language, nor does it offer a user language choice. This can create a locale or language-policy concern if the skill implicitly surfaces or relies on a language the user did not choose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.