Back to skill

Security audit

Automate Excel

Security checks for vulnerabilities and agentic risk

Overview

This Excel automation skill appears purpose-aligned, but its broad triggers and incomplete, unpinned command-line setup make it worth reviewing before installation.

Install only if you are comfortable with an exec-capable spreadsheet helper that may require Python package installation. Use a virtual environment, pin and review dependencies yourself, and invoke it only for explicit Excel/XLS/XLSX workbook tasks. Be aware that the advertised helper scripts are not present in the inspected artifact.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:63
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 63-79
Vulnerability Type: Unpinned and unverifiable Python dependencies
Risk Level: Medium

Vulnerable Code

markdown
**本地直接运行**:进入本 skill 所在目录(或把 `scripts/` 加入路径),先 `pip install -r scripts/requirements.txt`,再执行 `python scripts/脚本名.py --help` 看参数,或按上表传参运行。
bash
pip install openpyxl pandas xlrd
markdown
或使用 skill 自带:`pip install -r scripts/requirements.txt`

Technical Analysis

The Skill instructs users or agents to install openpyxl, pandas, and xlrd without exact versions or integrity hashes. Consequently, package resolution depends on mutable repository state at installation time rather than a reviewed and reproducible dependency set.

The alternative installation command references scripts/requirements.txt, but that file is absent from the audited artifact. Its contents therefore cannot be inspected, and the command cannot work with the package as supplied. The artifact contains only SKILL.md.

This is a supply-chain weakness rather than evidence that the named packages are malicious. Exploitation would require compromise of the configured package source, an unsafe future package release, or package-index configuration that resolves an unintended component.

Attack Path

  1. An agent loads the Skill and follows its documented setup procedure.
  2. The agent runs pip install openpyxl pandas xlrd without version or hash constraints.
  3. pip queries the environment's configured package indexes and resolves the packages available at that time.
  4. If an upstream release or configured index has been compromised, attacker-controlled installation or runtime code is installed.
  5. Package installation hooks may execute during installation; package code may also execute when imported during subsequent Excel processing.

The scripts/requirements.txt route is not directly exploitable from the audited artifact because that file is missing, but its absence pr ...[truncated 658 chars]

Remediation
View remediation

Remediation Suggestions

  1. Add an auditable dependency lock file to the project and pin every direct and transitive dependency to an exact reviewed version.
  2. Record cryptographic hashes and enforce them during installation:
    bash
    python -m pip install --require-hashes -r scripts/requirements.txt
    
  3. Generate and review the lock file using a dependency-management tool such as pip-tools, then commit the generated file with the Skill.
  4. Install dependencies in an isolated virtual environment under a non-privileged account:
    bash
    python -m venv .venv
    . .venv/bin/activate
    python -m pip install --require-hashes -r scripts/requirements.txt
    
  5. Configure trusted package indexes explicitly and prevent fallback to unreviewed or user-controlled indexes.
  6. Scan locked dependencies for known vulnerabilities and review updates before changing pinned versions.
  7. Either include the referenced scripts/ directory and scripts/requirements.txt in the distributed artifact or remove all claims that these files are bundled.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Most of the user-facing description and operating guidance are written exclusively in Chinese, with no indication that language selection is optional or user-driven. This can violate language/locale policy expectations when a skill implicitly constrains interaction to a specific language without opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger keywords are extremely generic terms such as 'writing', 'reading', and 'automate', which are likely to match ordinary user conversations unrelated to Excel automation. This can cause the skill to activate in unintended contexts and, because the skill exposes exec-capable workflows, may steer an agent toward unnecessary local command execution or file handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation condition states the skill should be used whenever the user needs to process Excel files, tabular data, bulk conversion, or report generation, which is broad enough to capture many common data tasks beyond the intended scope. Ambiguous invocation criteria increase the chance of accidental skill selection and unnecessary execution of local scripts via the exec tool in contexts where simpler, safer handling would suffice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.