Back to skill

Security audit

CSV文件处理专家

Security checks across malware telemetry and agentic risk

Overview

This CSV utility is mostly local and purpose-aligned, but it asks for an unexplained API key and uses overly broad activation language that could lead to unnecessary access.

Review before installing. Use it only for CSV-specific work, do not provide or export an API key unless the publisher clearly explains why it is needed, and confirm output directories before running split or export operations on sensitive data.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill is for local CSV processing, yet it instructs users to configure an external API key without any clear functional need. Unnecessary credential collection or setup increases the attack surface, can confuse users into exposing secrets to an unrelated workflow, and may normalize supplying sensitive tokens where they are not required.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The invocation guidance is overly broad and encourages use for generic file handling, document conversion, and content extraction beyond tightly scoped CSV operations. In an agent environment with read/exec/write tools, broad triggers can cause the skill to be selected for unrelated tasks, increasing the risk of unnecessary file access, command execution, or unsafe automation.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill description emphasizes processing features but does not clearly warn users that it writes files and can split one dataset into many outputs on disk. In agent contexts, omission of file-creation side effects can lead to unintended data duplication, persistence of sensitive records, or writes into unsafe locations.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.