Back to skill

Security audit

Excel公式工具

Security checks for vulnerabilities and agentic risk

Overview

This skill is framed as an Excel formula helper but asks for broad read, write, and command execution authority while also advertising unrelated file-processing and automation capabilities.

Review before installing. Use this only for spreadsheet formula help unless the publisher narrows the description and permissions; the current artifact may cause an agent to apply read, write, and command execution tools to tasks outside Excel formula assistance.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill is presented as an Excel-formula generator, but its description also claims broad file processing, document conversion, and content extraction abilities unrelated to that purpose. This mismatch can cause an agent to invoke the skill in contexts outside its real scope, increasing the risk of inappropriate access to files or execution paths enabled by the declared tools.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The premium feature table advertises unrelated capabilities such as chart generation, streaming large datasets, and scheduled synchronization without tying them to the stated formula-assistance purpose. Overstated or mismatched capabilities can mislead orchestration systems or users into granting broader trust and triggering the skill for tasks that require more sensitive permissions.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The examples and output schema describe generic content processing and content generation rather than Excel formula creation, contradicting the skill's declared purpose. This ambiguity weakens user and agent understanding of what the skill will do, making accidental misuse, overbroad invocation, or unsafe handling of arbitrary content more likely.

Vague Triggers

High
Confidence
96% confidence
Finding
The description says to use the skill whenever file processing, document conversion, format conversion, or content extraction is needed, which is far broader than Excel formula assistance. Because the skill also declares read, write, and exec tools, this broad trigger can cause an agent to route many unrelated tasks into a capability set that includes command execution, significantly expanding exposure.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The invocation guidance uses broad natural-language prompts like 'Just ask your AI assistant' with common phrases and limited scope constraints. In isolation this looks user-friendly, but in an agent ecosystem it can encourage over-triggering of the skill for loosely related requests, especially given the presence of exec/read/write permissions.

Static analysis

No suspicious patterns detected.