Back to skill

Security audit

电力交易96点转24点

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a focused Excel template editing aid, with the main risk being possible overwrite of the original workbook if used carelessly.

Before installing or using this skill, treat any workbook it edits as mutable data: work on a copy, keep backups of important templates, and avoid letting it overwrite the only version of a business-critical spreadsheet.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly tells the agent to modify an existing Excel template with minimal edits and preserve the workbook, but it does not instruct the user or agent to create a backup, save to a new file, or warn that the original may be altered. In a spreadsheet-editing workflow, in-place changes can irreversibly overwrite user data, formulas, formatting, or workbook state if the operation is wrong or partially applied.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The instruction to modify an existing template in place encourages overwriting the original workbook without any visible caution about file alteration or recovery. In the Excel/xlsx context, even a narrowly targeted change can corrupt formulas, workbook metadata, or hidden structures, making the absence of backup/overwrite guidance a real integrity risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.