Back to skill

Security audit

Excel多表格合并工具

Security checks for vulnerabilities and agentic risk

Overview

This Excel merge skill is mostly a straightforward local workbook utility, but it can copy attacker-controlled spreadsheet formulas into its generated output workbook.

Review before installing if you may process workbooks from untrusted parties. The skill should sanitize names and specifications that begin with =, +, -, @, tab, carriage return, or newline before writing the output workbook. For trusted internal spreadsheets, the core behavior is coherent and local-only.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
merge_script.py:185
Finding

Spreadsheet Formula Injection Through Unsanitized Workbook Values

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

L223-L227 的示例在调用 merge_excel_tables 后打印 len(data_dict),但 data_dict 是函数内部局部变量,主程序作用域中并不存在,因此该示例无法按注释意图工作。文档将其展示为可直接运行的“使用示例”,这与代码真实行为形成直接矛盾。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code contains natural-language comments, worksheet titles, headers, and user-facing print messages exclusively in Chinese. Under the policy rule, forcing a specific language without user opt-in or a documented locale justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.