Back to skill

Security audit

CSV数据分析-免费版

Security checks for vulnerabilities and agentic risk

Overview

This CSV skill is mostly a local analysis helper, but it asks for command execution while its documentation is inconsistent and advertises broader API, file, and command capabilities than the free CSV features support.

Install only if you intend to use it for local CSV stats and simple filtering, and review each command before execution. Avoid using it for external API work, broad automation, sensitive datasets, or non-CSV file processing unless the publisher narrows the documentation and provides the referenced implementation files.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
86% confidence
Finding
The skill markets itself as a lightweight, zero-extra-dependency CSV analyzer, but later claims generic external API integration capabilities. This inconsistency expands the apparent operational scope and can mislead users or agents into granting broader trust or using the skill for unrelated network-facing tasks not justified by its stated purpose.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
Advertising generic external API integration in a CSV-analysis skill creates unnecessary capability ambiguity. In an agent ecosystem, that ambiguity can cause overbroad invocation or permission assumptions, increasing the chance that sensitive data is sent to external services outside the user's expectation.

Intent-Code Divergence

Low
Confidence
74% confidence
Finding
The file states no additional API key is required, yet later includes guidance about API key leakage and environment-variable configuration. While not an exploit by itself, this contradiction suggests hidden or copy-pasted capability claims and undermines trust in the skill's documented security model.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The free-version documentation repeatedly says only stats and filter are supported, but the core functionality section advertises broad automation, file handling, API integration, and command execution. This mismatch can cause an agent or operator to over-trust the skill's scope and permit broader operations than intended.

Vague Triggers

Medium
Confidence
77% confidence
Finding
The invocation language is broad enough to match many generic data-analysis or reporting tasks, not just lightweight CSV stats/filter workflows. Overbroad triggering increases the chance the skill is selected in inappropriate contexts, where its exec permission and ambiguous documentation create avoidable security and reliability risk.

Vague Triggers

Medium
Confidence
79% confidence
Finding
The manifest and surrounding documentation present the skill as broadly applicable across developers, teams, and automation workflows without precise constraints. In agent routing, this can lead to excessive selection of a skill that has exec access despite only narrow, local CSV functionality being appropriate.

Static analysis

No suspicious patterns detected.