T09 · Insecure Skill Coding Practices
- Location
scripts/01-file-management.sh:117- Finding
Ready-to-run file-management script automatically renames and deletes the uploaded workbook
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This spreadsheet skill mostly matches its purpose, but several ready-to-run examples can delete workbook data or expose a sheet publicly without strong user confirmation.
Review before installing. Use this skill only with disposable or backed-up workbooks until its examples are made safer. Avoid running the bundled mutation and sharing scripts as-is on production spreadsheets; prefer one explicitly requested operation at a time, verify the target workbook/sheet/email, and be aware that workbook contents and samples are sent to the MaybeAI service.
scripts/01-file-management.sh:117Ready-to-run file-management script automatically renames and deletes the uploaded workbook
scripts/05-worksheets.sh:9Worksheet-management example unconditionally mutates the workbook and deletes hard-coded worksheet gid 1
scripts/12-permissions-sharing.sh:24Permission example temporarily exposes the target workbook as publicly editable
The description presents a comprehensive spreadsheet manipulation skill, while the supplied code chunk only demonstrates file-management API calls around Excel documents. Some overlap exists for upload/import and export, but the code’s actual scope is much narrower and also includes file administration actions like list/search/rename/delete that are not explicitly called out in the declared description. Because the primary implemented behavior is a subset focused on file lifecycle management rather than workbook/worksheet/formula operations, the description does not accurately represent this code chunk.
This is a clear description-behavior mismatch. The declared description says the skill manages spreadsheets broadly and specifically instructs users to use 'sheet-dashboard' instead for chart-authoring or dashboard-first workflows. However, the supplied code does exactly those dashboard/chart tasks: it calls add_chart, get_charts, set_chart, and delete_chart on a dashboard sheet, using SQL-driven ECharts specs, then manages pictures with add_picture, read_picture, and delete_picture. Those are materially different from the declared core capabilities like workbook profiling, formula execution/lineage, worksheet inspection, row/column changes, and import/export flows. The code’s primary purpose is chart/picture dashboard manipulation, which the description explicitly excludes.
Most of the script aligns with the declared spreadsheet-management purpose: upload, read/write, worksheet operations, formatting-like operations, formula recalculation, append/export, and SQL-backed sheet/chart data usage. However, the script materially includes chart creation through /api/v1/excel/add_chart with an ECharts JSON spec. The declared description explicitly excludes chart-authoring or dashboard-first workflows and directs those to a different skill (sheet-dashboard). Because the supplied code demonstrates chart authoring as part of this skill’s behavior, the description does not accurately represent the code’s actual capabilities.
Referenced artifact was not completely inspected
- It does not turn the main `SKILL.md` into a full API manual; long request bodies and examples belong in `references/` and `scripts/`.
The skill documents use of shell (bash, curl, jq) and outbound network access to a remote API, but it declares no explicit tool scope such as allowed tools or permissions. In an agent environment, that increases the chance the skill can trigger unintended command execution or exfiltration through broadly available tools rather than a tightly constrained interface.
The file includes a dedicated 'Chinese Rules' section that instructs behavior in Chinese rather than offering language choice or stating that Chinese is optional. Under the stated policy, forcing a specific language or locale without user opt-in is a natural-language policy violation.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- `read_sheet` on the key output range
- optionally `export`
Do not skip verification after:
- `sql/write_result`
- `update_data_keep_headers`
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Use this for large table-like .xlsx files: more than 10,000 rows in any worksheet, more than 100,000 populated cells across the workbook, or data shaped primarily as records.
curl -sS -X POST "$BASE_URL/api/v1/excel/import" \
-H "Authorization: Bearer $MAYBEAI_API_TOKEN" \
-F "engine=postgres" \
-F "file=@/absolute/path/to/file.xlsx"
The document exposes destructive and permission-changing operations such as delete, visibility, and permission updates without any warning, confirmation guidance, or least-privilege constraints. In an agent skill context, this increases the chance an automated workflow could delete files or broaden access unintentionally, causing data loss or unauthorized disclosure.
The documentation describes making sheets public and granting editor/viewer access without an explicit warning that these actions can expose sensitive spreadsheet data or allow unauthorized modification. In a spreadsheet-management skill, these operations directly affect confidentiality and integrity, so omission of cautions and confirmation guidance increases the risk of accidental oversharing or public edit enablement.
The document describes delete_worksheet and only advises confirming the gid or sheet name, but it does not clearly warn that deletion is destructive and may permanently remove data. In a spreadsheet-management skill that performs write operations, this omission can make an agent or operator more likely to execute an unsafe deletion without explicit user confirmation or recovery planning.
The documentation states that non-empty worksheet sample rows are sent to an LLM, but it does not provide an explicit privacy warning, consent step, or guidance to avoid sensitive workbooks. Because sample rows may contain personal, financial, or proprietary data, this creates a real data disclosure risk during normal use. The spreadsheet context makes this more dangerous because workbook samples often include production business records rather than synthetic examples.
The file says the service generates a Chinese natural-language workbook summary, which imposes a specific language on all users. There is no opt-in, language selection mechanism, or documented region-specific justification for this locale constraint.
The script uploads a local Excel file to a remote MaybeAI endpoint without any explicit privacy or data-handling warning. In the context of a spreadsheet skill, files may contain sensitive business or personal data, so silent transmission to a remote service can cause unintended disclosure.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# ── Import File by URL ───────────────────────────────────────────────────────
echo "=== Import File by URL ==="
curl -s -X POST "$BASE_URL/api/v1/excel/import_by_url" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"url": "https://example.com/data.xlsx"}' \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# ── List Files ───────────────────────────────────────────────────────────────
echo "=== List Files ==="
curl -s -X POST "$BASE_URL/api/v1/excel/list_files" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{}' \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# ── Search Files ─────────────────────────────────────────────────────────────
echo "=== Search Files ==="
curl -s -X POST "$BASE_URL/api/v1/excel/search_files" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"keyword": "sales"}' \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# ── Rename File ──────────────────────────────────────────────────────────────
echo "=== Rename File ==="
curl -s -X POST "$BASE_URL/api/v1/excel/rename_file" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d "{\"uri\": \"$DOC_URI\", \"new_filename\": \"renamed_sales_report.xlsx\"}" \
The script performs a destructive delete_file API call automatically after upload, with no confirmation prompt, dry-run mode, or safeguard to ensure the user intended permanent deletion. In a file-management skill, this is dangerous because normal execution can unintentionally delete user spreadsheets from the remote service, especially since the script chains multiple actions in one run.
Although labeled as external transmission, this line performs a destructive authenticated API call that deletes a remote file. In this skill context, automatic deletion is more dangerous because users may run the script expecting a demo or upload workflow and instead permanently remove a spreadsheet without clear consent.
# ── Delete File ──────────────────────────────────────────────────────────────
echo "=== Delete File ==="
curl -s -X POST "$BASE_URL/api/v1/excel/delete_file" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d "{\"uri\": \"$DOC_URI\"}" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# ── Export (Download) File ───────────────────────────────────────────────────
echo "=== Export File ==="
curl -s -o "./exported.xlsx" \
"$BASE_URL/api/v1/excel/export/$DOC_ID"
echo "Saved to ./exported.xlsx"
This shell script makes multiple authenticated curl requests that send the document ID/URI and retrieve spreadsheet data, which can expose user or organizational data to a remote service. While the script prints section headers, it does not provide any explicit warning that spreadsheet contents and metadata will be transmitted to an external API.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# ── List Worksheets ───────────────────────────────────────────────────────────
echo "=== List Worksheets ==="
curl -s -X POST "$BASE_URL/api/v1/excel/list_worksheets" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d "{\"uri\": \"$DOC_URI\"}" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# ── List Worksheets with Version Info ────────────────────────────────────────
echo "=== List Worksheets (with versions) ==="
curl -s -X POST "$BASE_URL/api/v1/excel/list_worksheets_version" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d "{\"uri\": \"$DOC_URI\"}" \
This request retrieves full sheet contents from the remote API and immediately prints the JSON response to stdout via jq, which can expose sensitive spreadsheet data in terminals, logs, CI output, or shell history captures. In a spreadsheet-reading skill this behavior is expected, but it still creates a real confidentiality risk when users handle production or regulated data without realizing the output will be broadly visible locally.
# ── Read Sheet ────────────────────────────────────────────────────────────────
echo "=== Read Sheet ==="
curl -s -X POST "$BASE_URL/api/v1/excel/read_sheet" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d "{\"uri\": \"$DOC_URI\", \"worksheet_name\": \"Sheet1\"}" \
No suspicious patterns detected.