Back to skill

Security audit

Excel Chart Report Developer

Security checks for vulnerabilities and agentic risk

Overview

This skill gives focused guidance for building and repairing Excel report workbooks and does not include hidden code, persistence, credential handling, or exfiltration behavior.

Install only if you want Codex to help create or modify Excel reporting workbooks. Review generated workbook scripts before running them on sensitive finance or operations files, especially when desktop Excel automation, data refresh, or PDF export is involved.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger sentence is malformed and extremely broad ('Help me ...'), which risks invoking the skill from ordinary conversational text rather than an explicit user request for this capability. In an agent ecosystem, broad matching can cause unintended routing, exposing the skill in contexts where workbook automation, file handling, or code generation was not actually requested.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger sentences are vague, malformed, and broad enough that the skill could activate in situations unrelated to the intended Excel-reporting scope. In an agent system, ambiguous activation criteria can cause inappropriate tool/skill selection, leading to unsafe automation, confusing outputs, or accidental handling of files and workflows outside the user's intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are generic and weakly constrained, such as broad requests for practical workflow help or direct skill invocation around common Excel-reporting tasks. In an agent ecosystem, this can cause accidental activation in contexts the user did not intend, expanding the skill’s opportunity to influence workflows or handle sensitive spreadsheet/reporting tasks without clear scoping.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

该技能文档整体以中文呈现,未见任何说明允许用户选择语言或仅在用户明确偏好中文时使用。根据语言/区域政策,若技能默认强制特定语言而未提供选择或正当限定,可能构成自然语言策略违规。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger description is overly broad and can activate on generic Excel/reporting-related requests without clear boundaries. This creates skill-routing ambiguity, increasing the chance the agent invokes this skill in unintended contexts and applies workflow or code guidance where a different, narrower skill should be used.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example trigger phrases are broad, unnatural, and insufficiently distinctive, which can cause accidental activation from ordinary conversation fragments. In an agent environment, ambiguous examples can bias matching logic toward false positives and result in misrouting or over-application of the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill enables implicit invocation with no visible trigger constraints, scope limits, or exclusion conditions in the manifest. That can cause the agent to invoke this workbook-manipulation skill in broader contexts than intended, increasing the chance of unintended file modification, data exposure through exports, or unsafe Office automation actions driven by ambiguous prompts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The invocation text uses vague language and a malformed pattern ('$software-data-excel-chart-developer-helper to handle ...') that is not tightly bound to a concrete user intent. This can increase accidental activation or ambiguous routing, especially because the skill covers file generation and automation workflows that may operate on user documents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This file presents the skill description and usage instructions entirely in Chinese, but does not state that language selection is optional or user-driven. Under the language/locale policy, documentation that imposes a specific language without opt-in can be a natural-language policy concern unless the locale restriction is justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.