T09 · Insecure Skill Coding Practices
- Location
scripts/generate_excel.py:54- Finding
Untrusted Data Written to Excel Without Formula Neutralization
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is an incomplete but purpose-aligned market-research reporting skill, with local report-output risks but no evidence of malicious behavior.
Install only if you are comfortable with a Chinese-language, partly unfinished reporting helper. Use explicit output paths, review generated spreadsheets before sharing, and treat any JSON input or scraped data as untrusted until the Excel formula-sanitization issue is fixed.
scripts/generate_excel.py:54Untrusted Data Written to Excel Without Formula Neutralization
The declared description presents a broader end-user research platform for overseas promotion resources, including country/platform/product-line analysis and Excel-format reporting. The supplied code chunk is much narrower: it parses an existing JSON input of search tasks/results, fabricates basic platform entries from those tasks, and saves a raw JSON file. Although this could be a supporting component of such a system, the actual behavior in this chunk does not implement the key declared outcomes such as true cross-country platform research, detailed extraction, or Excel dashboard generation. Therefore the description materially overstates what this code chunk actually does.
声明描述的是一个完整的“国际推广平台调研系统”,核心能力应包括跨国家资源调研、平台发现/收集,以及Excel看板式分析输出。而提供的代码只是一个离线评分脚本:读取现成平台JSON数据,依据影响力、受众、语言、价格、备注等字段打分,生成等级并保存结果。它不执行任何网络调研、数据采集、国家级资源搜索或报表看板生成。因此其实际行为仅覆盖了调研流程中很小的一部分“评分/排序”后处理,和声明的主要用途存在明显不匹配。
The declared description presents a full 'research system' that investigates overseas promotion platforms and produces Excel dashboard reports for analysis. The supplied code only builds search URLs from hardcoded query templates, groups them by country/type, and saves the resulting task list as JSON. This is related to the declared domain, but it is a much narrower preparatory utility rather than the described end-user research/reporting system. There are no undeclared dangerous behaviors, but there is a clear description-to-behavior gap in primary functionality and output.
The skill describes workflows that read local files, write reports, and perform network-based research, but it does not declare any explicit tool scope such as permissions or allowed-tools. In agents that honor declarative scoping, this can lead to over-broad execution authority or ambiguous enforcement, increasing the chance of unintended file access, report overwrite, or unrestricted outbound requests if the runtime defaults are permissive.
Overly broad trigger phrases can cause the skill to activate on loosely related requests, leading the agent to perform network research and file-generation actions when the user did not intend to invoke this skill. In a system with multiple skills, this increases the risk of prompt-routing mistakes, unnecessary data handling, and accidental use of external resources.
The manual trigger example "生成推广平台调研报告" is vague and lacks domain constraints, so the skill may be selected for generic marketing or platform-research requests outside the intended lithium-equipment context. That broad activation surface can misroute user prompts and trigger unnecessary browsing, parsing, or file output in contexts where another skill or no automation should be used.
The phrase '日语资料必备,英语接受度有限' states that Japanese-language materials are required, which is a natural-language locale constraint. Under the policy, forcing a specific language without user opt-in or a clearly documented justified regional compliance reason should be flagged.
This markdown file is written primarily in Chinese while providing search templates for multiple countries, but it does not state that the language choice is optional or region-specific. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue.
This code file contains natural-language strings and descriptions exclusively in Chinese, including the top-level purpose statement, CLI description, and user-facing status/error messages. Under the policy rule for language/locale, this appears to force a specific language without user opt-in or an explicit region-specific justification.
The docstrings and status messages for run_search, run_parse, and run_score indicate that the code searches platforms, fetches details, and scores results. In reality, each function contains a TODO, performs no actual processing, and merely constructs or rewrites filenames, which actively misrepresents the implemented behavior.
This code file contains natural-language documentation entirely in Chinese, and the CLI description/help text elsewhere in the file follows the same pattern. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation because users are not offered any locale choice or fallback.
The argparse description, argument help, and error/output messages are presented only in Chinese. This imposes a single language on all users without opt-in or documented justification, which matches the language/locale policy violation criteria.
The file presents itself entirely in Chinese and includes a scoring dimension that rewards support for Chinese manufacturers, indicating a locale-specific policy baked into the skill. Because the script does not offer any user opt-in, language choice, or explicit justification that it is intended only for a China-specific workflow, this is a natural-language locale/policy concern under the stated rules.
Line L37 states '韩语为主,英语辅助' as a directive, which imposes a specific language preference in the guidance. Under the policy, forcing a language or locale without user opt-in can be a natural-language policy violation unless it is explicitly framed as optional or justified as region-specific compliance.
Line L43 states '俄语资料必备' ('Russian-language materials are mandatory'), which imposes a specific language requirement in natural language. The file does not present this as an optional recommendation, offer alternatives, or explain a formal region-specific policy basis for requiring that language.
SQP-3 applies to all file types and includes language or locale policy violations. This markdown file presents all guidance only in Chinese and does not provide user opt-in, alternatives, or justification for restricting content to that language.
The manifest describes generating Excel-format dashboard reports for platform research, but does not indicate that the skill will place output directly in a user Desktop location by default. The code explicitly resolves Path.home()/Desktop and writes the generated report there when --skip-search is used, which is a broader filesystem side effect than the description suggests.
The module docstring is entirely in Chinese, describing the script's purpose without any indication that other languages are supported. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern, especially in a general-purpose script.
The argparse description and argument help strings are all Chinese-only, which constrains user interaction to a specific language without presenting a choice. This matches the language/locale policy violation category for natural-language content embedded in code.
No suspicious patterns detected.