Back to skill

Security audit

Excel Expert Free

Security checks across malware telemetry and agentic risk

Overview

This Excel helper is mostly a spreadsheet-advice skill, but it asks for broad write/exec authority and contains unrelated triggers and under-scoped command/file instructions.

Review this before installing. It does not show malware or destructive behavior, but it grants more authority than its Excel-help purpose needs and has unclear activation and command boundaries. Prefer installing only after the publisher narrows triggers to spreadsheet tasks, removes or tightly limits write/exec use, and clarifies whether it can generate macros or touch credential-backed data sources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The skill is presented as a spreadsheet formula/diagnostic assistant, but these sections broaden behavior into generic create/query/export/save/modify operations without clear scoping or safety boundaries. In a skill that also declares read/write/exec tools, this ambiguity can cause an agent to over-privilege the skill and perform filesystem or command actions that users would not reasonably expect from an Excel advisor.

Intent-Code Divergence

Medium
Confidence
82% confidence
Finding
The file inconsistently states that automation outputs macro code and error handling, while later claiming the free edition does not generate full VBA macros. Contradictory capability statements are dangerous because agents may choose the more permissive interpretation and emit executable macro content, increasing the chance of unsafe code generation in an environment with exec capability.

Context-Inappropriate Capability

Low
Confidence
77% confidence
Finding
Telling the agent to run network diagnostics such as ping is outside the stated spreadsheet-guidance scope and introduces unnecessary system/network interaction. Even though ping is low risk compared with arbitrary shell execution, it normalizes command use and can disclose network reachability or trigger unexpected outbound activity from an otherwise local productivity skill.

Vague Triggers

High
Confidence
90% confidence
Finding
An unrelated and overly broad trigger condition is dangerous because it can cause this skill to activate in contexts far outside spreadsheet help. Since the manifest also exposes read/write/exec tools, accidental invocation on design or general creative tasks could let the skill influence file or command operations where users did not intend to grant such behavior.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill advertises exec/write-capable behavior without clearly warning about system and data impact, which undermines informed use and safe agent planning. In practice, this can lead an agent or user to treat the skill as harmless advisory content while it actually has authority to modify files or invoke commands.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.