Back to skill

Security audit

xlsx-skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Excel spreadsheet helper with disclosed dependencies and no evidence of hidden, destructive, or unrelated behavior.

Install the Python packages in a virtual environment or other isolated workspace, pin versions if you need reproducible or enterprise-controlled installs, and review spreadsheet paths before running examples because they create or overwrite local Excel files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 14–23
Vulnerability Type: Unpinned and unverifiable third-party dependencies
Risk Level: Medium

Vulnerable Code

bash
pip install pandas openpyxl xlsxwriter
bash
# For chart support
pip install numpy

# For PDF export
brew install --cask libreoffice

Technical Analysis

The installation instructions retrieve third-party components without pinning reviewed versions, validating cryptographic hashes, or using a lockfile. Package resolution therefore depends on mutable package repository state at installation time. The resulting dependency set may change without any modification to the audited Skill.

This creates a supply-chain risk if a direct or transitive dependency, package maintainer account, repository, or package-resolution path is compromised. Python package installation may also execute installation or build logic. Merely importing a compromised installed package can execute attacker-controlled module initialization code.

The audit did not identify a currently malicious package or an intentionally unsafe package source. The vulnerability is the absence of dependency reproducibility and integrity controls.

Attack Path

  1. An attacker compromises a listed package, one of its transitive dependencies, a maintainer account, or the relevant package distribution channel.
  2. The attacker publishes a malicious release that remains compatible with unconstrained dependency resolution.
  3. A user or agent follows the installation commands in SKILL.md.
  4. The package manager resolves and installs the attacker-controlled release because no approved versions or hashes are specified.
  5. Malicious code executes during installation, build processing, or subsequent package import.
  6. The payload operates with the privileges and environmental access of the user running the installation or spreadsheet workflow.

Impact Asses

...[truncated 553 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace unconstrained package names with reviewed, exact version pins.
  2. Maintain dependencies in a lockfile or hash-locked requirements file generated from a trusted environment.
  3. Install Python dependencies with hash enforcement, such as:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  4. Pin and review transitive dependencies rather than controlling only direct dependencies.
  5. Configure package managers to use explicitly trusted registries and secure transport.
  6. Verify package signatures, checksums, or platform provenance where supported, including for LibreOffice.
  7. Perform installation and spreadsheet processing in an isolated virtual environment or container with least privilege, restricted filesystem access, and only necessary network access.
  8. Use automated dependency scanning and controlled update reviews before changing approved versions.
Vulnerability Patterns
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Unbounded Output

Medium
Category
Output Handling
Confidence
75% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · SKILL.md (reported line 568)May include surrounding context.

md
# Auto-adjust column widths
        for column in ws.columns:
            max_length = 0
            column_letter = column[0].column_letter
            for cell in column:
                try:

Static analysis

No suspicious patterns detected.