Back to skill

Security audit

Excel Formula Tool Free

Security checks across malware telemetry and agentic risk

Overview

This Excel formula helper is mostly a markdown instruction skill, but it asks for broader write, command execution, network callback, and generic data-operation authority than its narrow purpose explains.

Review before installing. Use it only if you are comfortable giving this skill write and command-execution authority, and avoid providing callback URLs or sensitive workbook data unless the publisher narrows and documents what may be modified, executed, or sent externally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is marketed as a narrowly scoped Excel formula assistant, but the body expands it into generic create/query/export/modify/delete behavior driven by arbitrary parameters. That scope drift increases the chance an agent will grant the skill broader operational authority than users expect, especially when paired with write and exec capabilities.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
For a personal Excel formula tool, introducing network-oriented behavior such as requests installation and connectivity troubleshooting is unnecessary and expands the attack surface beyond the stated purpose. This can normalize outbound access and external interactions in contexts where users expect offline formula assistance.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
Callback URL support enables the skill to send results or metadata to an arbitrary external endpoint, which is unrelated to simple Excel formula assistance. In an agent environment, this creates a clear exfiltration channel for user data, prompts, file contents, or execution results.

Vague Triggers

Medium
Confidence
88% confidence
Finding
Overly generic invocation wording like '执行核心功能' can cause the skill to activate on ambiguous requests without clear user intent. When combined with write and exec permissions, broad triggers increase the risk of unintended actions, file modification, or command execution.

Vague Triggers

Medium
Confidence
91% confidence
Finding
Broad create/query/export operation descriptions lack clear trigger boundaries and are not limited to Excel formula tasks. This ambiguity can let the skill over-match ordinary requests and perform actions outside its advertised domain.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill advertises read, write, and exec capabilities but provides no meaningful warning, limitation, or approval model for filesystem and command side effects. In a tool presented as a simple formula helper, that mismatch makes dangerous actions more likely to be invoked unexpectedly or socially engineered through benign-looking requests.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.