Back to skill

Security audit

Excel Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Excel workbook generator, but it uses a shared default password for client files and a fixed local output path, which can mishandle sensitive business workbooks.

Review before installing. This skill appears intended to generate Excel files, not to steal data or persist code, but do not rely on its default password for confidentiality. Use a unique user-supplied password per workbook, confirm the output path, and avoid using the default workflow for sensitive HR, finance, sales, or client data without cleanup and secure delivery practices.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:53
Finding

Hardcoded Shared Password for Client Workbooks

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 53–55
Vulnerability Type: Hardcoded credential and insecure password reuse
Risk Level: Medium

Vulnerable Code Snippet:

markdown
## Step 5: Deliver
- Save to `/Users/synapsefirm/.openclaw/workspace/excel-projects/[filename].xlsx`
- For client delivery: create a password-protected version with `Formly2026!` as default password

Technical Analysis

The skill embeds a static password directly in its instructions and directs the agent to reuse it for client-delivery workbooks. The password is visible to anyone who can inspect the skill and is identical across generated files. Consequently, workbook protection does not provide a meaningful confidentiality boundary against anyone familiar with this convention.

Reusing the password also expands the scope of a disclosure: knowledge of the credential for one workbook can provide access to every workbook generated according to the same instruction. The project does not include the referenced generator script, so the precise protection mechanism—including whether it provides encryption or only workbook/worksheet editing protection—could not be verified.

Attack Path

  1. The skill generates a client workbook and protects it using the documented default password.
  2. An attacker obtains the workbook through unauthorized file access, accidental disclosure, email forwarding, shared storage, or another distribution channel.
  3. The attacker reads the password from SKILL.md or learns the shared convention from a previously delivered workbook.
  4. The attacker supplies Formly2026! when prompted to open or modify the workbook.
  5. If the implementation applies actual file encryption, the attacker decrypts and reads the workbook. If it applies only workbook or worksheet protection, the attacker bypasses the intended editing restrictions.
  6. The attacker repeats the same process against other workbooks pro ...[truncated 787 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the hardcoded default password from SKILL.md.
  2. Generate a unique password for every protected workbook using a cryptographically secure random-number generator.
  3. Use a sufficiently long random value, such as at least 16 characters containing multiple character classes, or an equivalently strong generated passphrase.
  4. Do not write generated passwords to source files, logs, workbook metadata, command histories, or predictable output files.
  5. Deliver the password through a secure channel separate from the workbook.
  6. Confirm that the selected Excel library and workflow provide authenticated file encryption rather than only worksheet, workbook-structure, or editing protection.
  7. Allow users to supply credentials through a secure secret-input mechanism when organizational password-management requirements apply.
  8. Rotate the exposed shared password immediately and re-protect previously delivered sensitive workbooks with unique credentials where feasible.
  9. Add automated checks that reject known default passwords and prevent password reuse across generated client files.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description and 'When to Use' section activate on generic phrases like building an Excel file, spreadsheet, tracker, or report, which are broad requests that may arise in many contexts. The file does not provide narrowing constraints or negative examples to clarify when this skill should not be invoked.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs saving files to a fixed local workspace path and creating client-delivery artifacts without requiring user awareness or consent about file creation, storage location, or sensitivity of workbook contents. In a skill likely to process business, HR, financial, or sales data, silent persistence can expose confidential data through unintended retention, local access, or mishandled delivery workflows.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly directs creation of password-protected deliverables using a single hardcoded default password, which undermines the purpose of protection because anyone who knows or guesses the documented password can access all generated files. In an Excel-generation skill, this is not necessary for core functionality and creates a repeatable weak-secret pattern that can expose sensitive workbook contents.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Using a fixed default password for all client-delivered files creates a predictable credential that defeats confidentiality across every generated workbook. Because this skill targets professional reports and dashboards that may include financial, HR, inventory, or sales data, a reused documented password substantially increases the likelihood of unauthorized disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.