Back to skill

Security audit

Image To Excel

Security checks for vulnerabilities and agentic risk

Overview

This skill has a useful, coherent image-to-Excel purpose, but its documented shell workflow and helper script create avoidable command-execution and spreadsheet-safety risks.

Review before installing. The skill is not clearly malicious, but it should be hardened to pass JSON through stdin or an argument-vector API, remove automatic pip installation, declare a pinned dependency, restrict output paths, document overwrite behavior, and neutralize formula-like cell values from OCR before saving workbooks.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:39
Finding

Shell Command Injection Through Untrusted JSON Data

Content
View full analysis
'' ``` ### Technical Analysis The skill instructs the agent to place image-derived, user-controlled JSON directly inside a shell command. Wrapping the JSON in single quotes does not make this safe because a cell value can itself contain a single quote. If the agent follows this command template literally, an attacker can place shell metacharacters in table text, terminate the quoted JSON argument, append another command, and comment out the remainder. JSON encoding does not inherently escape characters for safe interpolation into a POSIX shell command. For example, extracted content containing a value structurally similar to the following could break the shell quoting: ```text '; attacker_command; # ``` The issue exists in the documented execution workflow even though `gen_excel.py` itself does not invoke a shell for this data. ### Attack Path 1. An attacker prepares an image containing table text with a single quote followed by shell syntax. 2. The image extraction model preserves the malicious text in the generated JSON array. 3. The agent substitutes that JSON directly for `` in the documented command. 4. The embedded single quote terminates the shell argument. 5. The shell interprets the remaining text as a separate command. 6. The injected command executes with the operating-system privileges and environment access of the agent process. ### Impact Assessment Successful exploitation can provide arbitrary command execution under the account running the skill. The attacker could read or modify files accessible to that account, alter generated artifacts, access environment variables, invoke network utilities, or execute additional local programs. The precise scope is limited by the privileges, sandboxing, filesystem a ...[truncated 51 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/gen_excel.py:10
Finding

Unpinned Automatic Dependency Installation at Runtime

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/gen_excel.py:47
Finding

Spreadsheet Formula Injection in Generated Excel Files

Content
View full analysis
1 for r_idx, row in enumerate(rows): for c_idx, val in enumerate(row): cell = ws.cell(row=r_idx + 1, column=c_idx + 1, value=str(val) if val else "") ``` ### Technical Analysis The script writes OCR-derived, user-controlled values directly into workbook cells. Values beginning with formula indicators such as `=`, `+`, `-`, or `@` are not neutralized or explicitly forced to text. Spreadsheet applications can interpret such values as formulas when the generated workbook is opened. Depending on the spreadsheet client and its security settings, malicious formulas may initiate external requests, expose workbook data, present misleading hyperlinks or prompts, or invoke dangerous legacy spreadsheet functionality. The vulnerability is especially relevant here because the source is an image: an attacker can visually embed a formula-like string in a table and rely on OCR to transfer it into the workbook. ### Attack Path 1. An attacker supplies an image containing a table cell beginning with a spreadsheet formula marker, such as `=`. 2. The image extraction process returns the malicious value as a JSON string. 3. The script converts the value to a string and passes it directly to `openpyxl`. 4. The generated workbook contains the attacker-controlled formula. 5. A user opens the workbook in a spreadsheet application. 6. The application evaluates or otherwise processes the formula according to its security configuration. ### Impact Assessment The immediate target is the user who opens the generated workbook. Potential consequences include external network requests, disclosure of data included in formula arguments, deceptive content, and abuse of client-specific or legacy spreadsheet features. The exact impact depends on th ...[truncated 135 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes a shell command (python3 scripts/gen_excel.py ...) but does not declare any tool restrictions or allowed tools. In an agent environment, missing tool scoping increases the attack surface because the skill can trigger command execution without an explicit permission boundary, making misuse or prompt-driven abuse more likely.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Runtime package installation is not required for converting JSON table data into an Excel file and expands the skill's capabilities beyond its stated function. If triggered, it may fetch and execute code from external package sources, undermine reproducibility, and violate restricted or offline execution assumptions.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
92% confidence
Finding

The script executes a package installation at runtime via pip when openpyxl is missing. This introduces an unnecessary code-execution and supply-chain surface for a skill whose purpose is only to generate an Excel file, and it can cause unreviewed network activity and dependency changes in the execution environment.

Content

Scanner excerpt · scripts/gen_excel.py (reported line 17)May include surrounding context.

python
except ImportError:
    print("Missing openpyxl, installing...")
    import subprocess
    subprocess.check_call([sys.executable, "-m", "pip", "install", "openpyxl", "-q"])
    from openpyxl import Workbook
    from openpyxl.styles import Font, Alignment, Border, Side, PatternFill
    from openpyxl.utils import get_column_letter

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The markdown instructs the agent to generate and save an .xlsx file via a script and provides an example output path, but it does not mention any caution about creating files on disk or whether an existing file at that path could be overwritten. Because this is a markdown skill description covering a data-affecting operation, a brief user warning would improve transparency.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.