Back to skill

Security audit

Excel表格处理工具

Security checks across malware telemetry and agentic risk

Overview

This Excel skill is probably intended for workbook handling, but it asks for broad read/write/command authority and gives vague guidance about file processing, API keys, and command execution.

Review this before installing if you expect a narrow Excel-only helper. Use it only with workbooks you are comfortable letting an agent read or modify, avoid providing unrelated files, and do not set an API key unless you know what service it is for. Prefer explicit prompts that require confirmation before overwriting files or running commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The activation guidance is overly broad and could cause the skill to be selected for loosely related file-processing or extraction tasks outside its safe, intended scope. In a skill with read/write/exec tools, overbroad routing increases the chance of unnecessary file access, unintended modification, or command execution during unrelated workflows.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill can modify workbook files and has exec capability in metadata, yet the Markdown lacks a clear warning about destructive changes and command execution. This is dangerous because users may invoke it without informed consent, increasing the risk of silent file overwrite, unsafe command use, or broader host interaction than expected.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.