Back to skill

Security audit

Create an Excel (.xlsx) file containing formatted data.

Security checks for vulnerabilities and agentic risk

Overview

This Excel generator appears to match its purpose, but it automatically installs code dependencies and can write or overwrite spreadsheet files in arbitrary writable locations without clear user control.

Review this skill before installing in a shared or sensitive agent environment. Prefer running it only in a sandboxed workspace with no valuable spreadsheet files in writable paths, preinstall a pinned openpyxl dependency through your normal package process, and require explicit user confirmation for output filenames and overwrites. Treat workbook cell values from untrusted sources carefully because formula-like strings may remain active in the generated spreadsheet.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
generate_excel.py:17
Finding

Automatic Installation of an Unpinned Dependency During Module Import

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
generate_excel.py:43
Finding

Caller-Controlled Output Path Permits File Creation and Overwrite Outside the Intended Directory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
generate_excel.py:59
Finding

Untrusted Cell Values Can Be Written as Executable Spreadsheet Formulas

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (7)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This skill contains built-in self-install behavior that invokes pip and subprocess automatically, causing side effects outside the skill's core Excel-generation purpose. In an agent or automation context, implicit dependency installation can lead to unreviewed code execution, supply-chain exposure, environment drift, and unexpected outbound network access.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · generate_excel.py (reported line 16)May include surrounding context.

python
import_name = package_name
        
    try:
        __import__(import_name)
    except ImportError:
        print(f"⚠️ 正在自动安装缺少的核心库: {package_name} ...")
        try:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
95% confidence
Finding

The code automatically executes pip via subprocess at runtime, which performs network-enabled package installation and arbitrary setup/build code execution in the current environment. Even though the package name is fixed, this expands the attack surface significantly and is unsafe behavior for a skill because dependency installation should not occur implicitly during normal execution.

Content

Scanner excerpt · generate_excel.py (reported line 20)May include surrounding context.

python
except ImportError:
        print(f"⚠️ 正在自动安装缺少的核心库: {package_name} ...")
        try:
            subprocess.check_call([sys.executable, "-m", "pip", "install", package_name])
            print(f"✅ {package_name} 安装成功!")
        except Exception as e:
            print(f"❌ 安装失败: {e}")

Unbounded Output

Medium
Category
Output Handling
Confidence
75% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · generate_excel.py (reported line 91)May include surrounding context.

python
# 4. 自动调整列宽 (简单的自适应逻辑)
        for col in ws.columns:
            max_length = 0
            column = col[0].column_letter # 获取列号字符 (A, B, C...)
            for cell in col:
                try:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The function writes a user-supplied filename directly to disk without checking for existing files, restricting output location, or requiring confirmation before overwrite. In an agent setting this can overwrite local files or place artifacts in unintended paths, especially if filename is influenced by upstream prompts or external input.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger keywords are broad and generic, including terms like 'Excel', 'Spreadsheet', and non-English synonyms without any disambiguation rules. This can cause the skill to activate in contexts where the user did not explicitly request file generation, increasing the chance of unintended tool execution, misrouting, or abuse through prompt steering.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The trigger list mixes English and Chinese keywords, implying language-specific activation behavior, but the document does not explain whether this multilingual handling is user-selectable or limited to a defined locale context. This can create an implicit language/locale policy issue because the skill behavior is shaped by fixed language assumptions without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.