Back to skill

Security audit

Excel Chart Report Developer

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Excel reporting helper skill with some broad trigger wording, but no evidence of hidden execution, persistence, credential access, or malicious behavior.

Install this if you want Codex to help design, generate, or troubleshoot Excel report workbooks. Be aware that its trigger wording is broad, so confirm the task is actually about Excel/XLSX reporting before allowing it to edit important workbooks; keep backups of business spreadsheets before automation runs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger sentences are generic, malformed, and broad enough that they could match unrelated user requests about Excel or reporting, causing unintended skill invocation. In an agent setting, ambiguous activation increases the chance that the wrong automation path is selected, which can lead to inappropriate file handling, workbook modification, or data processing without clear user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are extremely generic and grammatically broad, so they can match ordinary user requests that merely mention Excel reporting concepts rather than intentionally invoking this skill. In an agent environment, this increases the chance of unintended activation, which can cause the wrong workflow to run, produce incorrect outputs, or interfere with user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation description is very broad and mixes multiple loosely bounded domains and user intents, which can cause the skill to trigger in contexts that only partially match the intended Excel-reporting use case. Over-broad triggering is dangerous because it can hijack unrelated requests, route users into an unsuitable workflow, and increase the chance of incorrect guidance or unintended tool/code generation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The keyword list contains generic terms such as 'dashboard' and 'conditional formatting' without scope constraints or negative examples, so ordinary software/data conversations may activate the skill unintentionally. This matters because keyword-only activation can override better-matched skills, produce irrelevant outputs, and create unsafe assumptions about files, automation, or spreadsheet operations the user did not request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger sentence is overly broad and malformed, which can cause the skill to activate for loosely related or ordinary requests instead of narrowly scoped Excel-reporting tasks. In an agent setting, ambiguous activation expands the skill's reach and can route unrelated user input into workbook-generation or automation flows the user did not intend to invoke.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The invocation examples are ambiguous, malformed, and repetitive, leaving the trigger boundary unclear. This increases the chance of accidental or adversarial invocation, especially because the examples include generic framing and incomplete phrasing that a router may match too broadly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

Although this is labeled as a Chinese README, key user-facing content including the title, requirement description, workflow description, keywords, and trigger phrases is presented in English. This can amount to a language-policy issue because the file implicitly forces English for core usage guidance without giving users an opt-in choice or explaining the locale decision.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

文件名和全文内容表明该技能以中文(zh-CN)呈现,但文档中未说明这是可选语言版本,也未向用户提供语言偏好选择。按规则,未提供用户选择而强制特定语言/locale 可能构成自然语言政策问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.