Back to skill

Security audit

Excel Ninja Free

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Excel automation skill that uses local file reads, command execution, and output-file creation in ways that mostly match its stated purpose.

Install only if you want an agent to run local Python commands for Excel/CSV files. Use a test copy of important spreadsheets, specify output filenames or directories clearly, and review any batch plan before processing a folder.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill declares extremely broad trigger keywords such as generic file-processing and office-task phrases, which can cause an agent to invoke this skill for requests outside the user's actual intent. In an agent environment with exec access, over-broad matching increases the chance of unintended local file reads/writes or script execution against user data.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill repeatedly instructs the agent to generate output files, split inputs into many files, and batch-convert directory contents, but it does not prominently warn that these operations create or may overwrite artifacts on disk. In an automated agent context, this can lead to unintended data modification, clutter, or destructive writes in user workspaces.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.