T08 · Insecure Dependencies
- Location
generate_excel.py:17- Finding
Automatic Installation of an Unpinned Dependency During Module Import
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Excel generator appears to match its purpose, but it automatically installs code dependencies and can write or overwrite spreadsheet files in arbitrary writable locations without clear user control.
Review this skill before installing in a shared or sensitive agent environment. Prefer running it only in a sandboxed workspace with no valuable spreadsheet files in writable paths, preinstall a pinned openpyxl dependency through your normal package process, and require explicit user confirmation for output filenames and overwrites. Treat workbook cell values from untrusted sources carefully because formula-like strings may remain active in the generated spreadsheet.
generate_excel.py:17Automatic Installation of an Unpinned Dependency During Module Import
generate_excel.py:43Caller-Controlled Output Path Permits File Creation and Overwrite Outside the Intended Directory
generate_excel.py:59Untrusted Cell Values Can Be Written as Executable Spreadsheet Formulas
This skill contains built-in self-install behavior that invokes pip and subprocess automatically, causing side effects outside the skill's core Excel-generation purpose. In an agent or automation context, implicit dependency installation can lead to unreviewed code execution, supply-chain exposure, environment drift, and unexpected outbound network access.
Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.
import_name = package_name
try:
__import__(import_name)
except ImportError:
print(f"⚠️ 正在自动安装缺少的核心库: {package_name} ...")
try:
The code automatically executes pip via subprocess at runtime, which performs network-enabled package installation and arbitrary setup/build code execution in the current environment. Even though the package name is fixed, this expands the attack surface significantly and is unsafe behavior for a skill because dependency installation should not occur implicitly during normal execution.
except ImportError:
print(f"⚠️ 正在自动安装缺少的核心库: {package_name} ...")
try:
subprocess.check_call([sys.executable, "-m", "pip", "install", package_name])
print(f"✅ {package_name} 安装成功!")
except Exception as e:
print(f"❌ 安装失败: {e}")
Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.
# 4. 自动调整列宽 (简单的自适应逻辑)
for col in ws.columns:
max_length = 0
column = col[0].column_letter # 获取列号字符 (A, B, C...)
for cell in col:
try:
The function writes a user-supplied filename directly to disk without checking for existing files, restricting output location, or requiring confirmation before overwrite. In an agent setting this can overwrite local files or place artifacts in unintended paths, especially if filename is influenced by upstream prompts or external input.
The trigger keywords are broad and generic, including terms like 'Excel', 'Spreadsheet', and non-English synonyms without any disambiguation rules. This can cause the skill to activate in contexts where the user did not explicitly request file generation, increasing the chance of unintended tool execution, misrouting, or abuse through prompt steering.
The trigger list mixes English and Chinese keywords, implying language-specific activation behavior, but the document does not explain whether this multilingual handling is user-selectable or limited to a defined locale context. This can create an implicit language/locale policy issue because the skill behavior is shaped by fixed language assumptions without explicit opt-in or justification.
No suspicious patterns detected.