Back to skill

Security audit

Excel XLSX Formula Cleanup

Security checks for vulnerabilities and agentic risk

Overview

This skill gives disclosed, purpose-aligned guidance for safely repairing Excel workbooks and does not ship executable code or hidden persistence.

Before installing, treat this as a workbook-repair helper that may inspect sensitive spreadsheet contents when invoked. Use copies of important files, confirm before modifying macros or business-critical workbooks, and avoid invoking it for generic Excel questions that do not require workbook inspection or repair.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger sentences are generic, malformed, and broad enough that an agent could invoke this skill in contexts only loosely related to Excel workbook repair. Over-broad activation increases the chance of unintended delegation, causing the agent to apply workbook-manipulation guidance to inappropriate tasks or untrusted files, which is especially risky for a skill that may inspect macros, formulas, and embedded business logic.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are broad, awkwardly templated, and not tightly scoped to explicit user intent, which increases the chance the skill is invoked when a request only loosely mentions Excel troubleshooting. In an automation context, unintended invocation can cause the agent to inspect or modify workbooks unnecessarily, raising the risk of workflow disruption or accidental handling of sensitive spreadsheet content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

文件名和内容整体限定为 zh-CN 版本,但文档中没有说明这是可选语言,也没有提供用户语言偏好或切换方式。按规则,这种未经过用户选择的固定语言/地区约束属于自然语言层面的策略问题。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is broad enough that ordinary Excel-related requests could trigger this skill even when the user did not ask for workbook inspection or automation. Over-broad activation can route unrelated user content into a workflow that assumes file handling, formula inspection, VBA preservation, or automation, increasing the chance of unintended actions or disclosure of sensitive spreadsheet context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger section uses generic keywords like 'microsoft excel', 'xlsx', 'formula', and 'power query' without scope boundaries or negative examples. This makes accidental invocation likely in many normal office-product conversations, which can cause the agent to apply overly powerful or mismatched workbook-handling guidance in contexts where it is unnecessary or risky.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill metadata is broadly scoped and allows implicit invocation, so routine Excel-related requests could trigger this skill even when the user did not explicitly ask for workbook inspection or modification. Because this skill is described as inspecting and fixing formulas, ranges, Power Query, pivots, VBA, and cleanup issues, unintended invocation could expose sensitive workbook contents or cause unintended file modifications in a wider set of contexts than necessary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger sentence is so broad and awkwardly phrased that it could match ordinary user requests unrelated to this specific Excel/XLSX maintenance skill. Over-broad activation increases the chance the agent invokes the skill in the wrong context, causing unintended file-handling or analysis behavior and reducing reliability of safety boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This trigger is ambiguous and insufficiently scoped to the Excel/XLSX repair workflow, so it may activate on vague requests for a 'practical workflow' that do not actually require workbook-preserving Excel operations. In an agent setting, ambiguous routing can expose sensitive spreadsheets to unnecessary processing or cause the wrong skill to take actions on files it should not touch.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

A Chinese-language README includes core usage and trigger content in English, including the main workflow description and all sample trigger phrases. This can effectively impose an English interaction pattern on users of the zh-CN variant without documenting a language option or opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger section lacks precise activation guidance and negative examples, which makes accidental or inconsistent invocation more likely. While this is less severe than direct code execution or prompt injection, poor routing guidance in a file-manipulation skill can still lead to misapplication, unnecessary access to business spreadsheets, and downstream integrity issues.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.