Back to skill

Security audit

Maybeai Sheet Cli Skill Publish Cdh7d1wj

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed MaybeAI spreadsheet CLI helper, with powerful but purpose-aligned spreadsheet editing, deletion, import/export, and sharing capabilities.

Install only if you want an agent to operate MaybeAI spreadsheets with your MAYBEAI_API_TOKEN. Review requests before allowing deletion, public sharing, editor grants, imports of sensitive files, or exports to local paths, and prefer dry-run plus verification for destructive or unfamiliar changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill exposes file read, file write, and network-capable workflows but does not declare any permissions or capability boundaries. That mismatch can cause agents or operators to invoke the skill with an incomplete understanding of its side effects, increasing the risk of unintended local file modification, remote data access, or data exfiltration through CLI-mediated operations.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The documented purpose presents the skill as a spreadsheet-operation interface, but the analyzed behavior extends into repository inspection, local metadata rewriting, and external PyPI lookups. Hidden maintenance or self-modifying behaviors expand the trust boundary beyond user-expected spreadsheet tasks and could be abused to alter adjacent files or leak project metadata under the guise of routine spreadsheet assistance.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The invocation description is extremely broad, covering inspection, import/export, writes, SQL, refreshes, dashboards, and sharing. Over-broad routing criteria can cause this powerful skill to trigger in many contexts, increasing the chance that an agent selects a networked, file-writing, destructive-capable tool when a narrower, safer skill would suffice.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The reference provides direct commands to make a spreadsheet public, grant editor access, or remove user access, but it does not instruct the agent to obtain explicit user confirmation or warn about confidentiality and integrity consequences before performing those actions. In an agent skill context, this increases the chance of accidental oversharing or unauthorized permission changes when a user request is ambiguous or when sensitive sheets are involved.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.