Back to skill

Security audit

Xlsx Generation

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Excel spreadsheet generator, with the main practical caution being ordinary file creation and output-path handling.

Before installing, expect the skill to create Excel files and confirm the filename and destination when using it, especially with sensitive data or existing files. Use it in Chinese-language contexts unless you explicitly ask the agent to adapt language and fonts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases include very generic terms like '生成Excel表格' and '制作Excel', which can match ordinary user requests and cause this skill to activate unexpectedly. Over-broad activation increases the chance that the agent will enter a file-generation workflow without clear user intent, potentially leading to unintended file creation or mishandling of user data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to save output as an .xlsx file but does not specify where the file will be written, whether overwriting can occur, or that persistent artifact creation will happen. In an agent environment, silent file creation can surprise users, leak sensitive data into unintended locations, or overwrite existing files if path handling is unsafe.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file specifies only Chinese typography choices such as 黑体、宋体、楷体 and presents the skill content entirely in Chinese, with no indication that users may choose another language or locale. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file title and core instruction require the skill to operate in Chinese (e.g., the entire requirements checklist and output conventions are specified only in Chinese), with no indication that users may choose another language. This is a natural-language locale policy concern because it imposes a specific language by default rather than offering opt-in or documenting a region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The description and operating instructions are presented entirely in Chinese, but the file does not state that language selection is optional or user-driven. This can amount to a language/locale policy issue if the skill implicitly forces one language for all users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all instructions and operational guidance exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally region-specific. That creates a natural-language policy concern under the language/locale rule because the file effectively forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This file presents all task goals, steps, and output examples exclusively in Chinese. Under the policy for natural-language violations, forcing a specific language without user opt-in can be a locale policy issue when no alternative or choice is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown skill specifies all instructions and examples in Chinese, which can constitute a language/locale policy issue when the skill implicitly forces one language for all users. There is no visible statement offering an alternative language or indicating that Chinese is an optional or region-specific setting.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s natural-language instructions and examples are entirely in Chinese, which can amount to a language/locale restriction if users are not given an opt-in or alternative. The content does not state that the skill is region-specific or provide any language selection, so it may violate organizational language-choice policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.