Back to skill

Security audit

WPS Excel Processing

Security checks for vulnerabilities and agentic risk

Overview

This spreadsheet skill is mostly purpose-aligned, but its formula recalculation helper can silently rewrite workbook files in place without clear user-facing consent or safeguards.

Review carefully before installing if you may process important or untrusted spreadsheets. Prefer running it only on copies or generated output files, and avoid relying on the documented timeout as a real execution limit.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/recalc.py:88
Finding

Unbounded XLSX Archive Decompression Can Exhaust Memory

Content
View full analysis

Vulnerability Details

File Location: scripts/recalc.py, lines 88–90
Vulnerability Type: Uncontrolled resource consumption through unbounded ZIP decompression
Risk Level: Medium

Vulnerable Code

python
with zipfile.ZipFile(filepath, 'r') as zin:
    file_list = zin.namelist()
    contents = {name: zin.read(name) for name in file_list}

Technical Analysis

XLSX files are ZIP archives. The implementation enumerates every archive member, decompresses each member in full, and retains all resulting data in the contents dictionary.

No limits are imposed on:

  • The number of archive members
  • The uncompressed size of an individual member
  • The aggregate uncompressed archive size
  • The ratio between compressed and uncompressed sizes

Consequently, an attacker-controlled workbook can contain highly compressed data that expands far beyond its on-disk size. Because all expanded members remain resident simultaneously, processing such a workbook can consume all memory available to the Agent process.

Attack Path

  1. An attacker constructs a syntactically acceptable XLSX archive containing one or more entries with extremely high compression ratios.
  2. The attacker supplies the workbook for spreadsheet processing.
  3. The Agent invokes recalc() as directed by the Skill.
  4. Formula processing reaches _inject_cached_values().
  5. The dictionary comprehension calls zin.read() for every archive member.
  6. The malicious entries expand in memory while all previously expanded entries remain retained.
  7. The worker runs out of memory, terminates, or destabilizes the host environment.

Impact Assessment

Successful exploitation does not grant additional privileges or provide direct access to confidential data. Its primary effect is denial of service within the privileges of the process running the Skill.

Potential consequences include:

  • Termination of the Agent worker through out-of-memory conditions
  • Failure or interruption of the cu ...[truncated 263 chars]
Remediation
View remediation

Remediation Suggestions

Validate the archive before decompressing or parsing its contents:

  1. Use ZipFile.infolist() to inspect metadata before reading any member.
  2. Enforce a strict maximum member count.
  3. Reject members whose declared uncompressed size exceeds a configured per-entry limit.
  4. Reject archives whose aggregate declared uncompressed size exceeds a configured workbook limit.
  5. Detect suspicious compression ratios, including entries with very small compressed sizes and disproportionately large uncompressed sizes.
  6. Stream-copy unchanged archive members instead of loading the complete archive into a dictionary.
  7. Read entries incrementally with explicit byte limits rather than using unrestricted zin.read(name).
  8. Run workbook processing in an isolated worker with operating-system memory and CPU limits.
  9. Treat malformed archives, encrypted entries, duplicate names, and path-traversal-style member names as validation failures.
  10. Write the modified workbook to a separate temporary file and replace the original atomically only after successful validation and processing.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/recalc.py:324
Finding

Ignored Recalculation Timeout Enables Computation Denial of Service

Content
View full analysis

Vulnerability Details

File Location: scripts/recalc.py, lines 324–330; calculation occurs at lines 218–219
Vulnerability Type: Uncontrolled execution duration and misleading timeout contract
Risk Level: Medium

Vulnerable Code

python
def recalc(filename: str, timeout: int = 60) -> dict:
    """Recalculate all formulas and scan for errors.

    Args:
        filename: Absolute path to the xlsx file.
        timeout: Reserved for compatibility (not used by the pure-Python engine).

The unrestricted calculation is performed as follows:

python
xl_model = formulas.ExcelModel().loads(abs_path).finish()
solution = xl_model.calculate()

Technical Analysis

The public function accepts a timeout argument, and the Skill documentation presents a default timeout of 60 seconds. The implementation explicitly states that the parameter is not used, however, and executes workbook loading and formula evaluation synchronously without a deadline.

An attacker can therefore provide a workbook containing a very large or computationally expensive formula graph. Processing can continue beyond the caller-supplied timeout and monopolize CPU and memory for an uncontrolled period. Callers may incorrectly rely on the API contract and assume that processing will stop after the configured interval.

A thread-based timeout alone would not reliably address this issue because Python cannot safely terminate arbitrary computation running in another thread. Effective enforcement requires process isolation or equivalent external resource controls.

Attack Path

  1. An attacker creates a valid workbook containing a large volume of formulas, costly dependency graphs, or formula structures that are unusually expensive for the formulas engine.
  2. The attacker submits the workbook for processing.
  3. The Agent invokes recalc(filename, timeout=60).
  4. ExcelModel().loads(...).finish() constructs the model, and calculate() evaluates it synchronously.
  5. N ...[truncated 935 chars]
Remediation
View remediation

Remediation Suggestions

Enforce the timeout as a real security boundary:

  1. Move workbook loading and formula calculation into a dedicated subprocess.
  2. Wait for that subprocess using the caller-provided timeout.
  3. Terminate and reap the subprocess when the deadline expires.
  4. Return a distinct timeout status without falling back to another potentially expensive operation.
  5. Apply operating-system resource limits for CPU time, address space, file size, and open files.
  6. Limit workbook dimensions, formula count, formula length, and dependency-graph complexity before calculation.
  7. Cap concurrent recalculation workers to prevent repeated malicious submissions from exhausting the service.
  8. Use isolated temporary storage and avoid granting the calculation worker unnecessary filesystem or network access.
  9. Document the maximum accepted workbook complexity and the precise timeout behavior.
  10. If enforceable cancellation cannot be implemented, remove the unused timeout parameter and avoid claiming that processing is time-bounded; this improves correctness but does not replace resource isolation.
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill instructs code to access environment variables such as OUTPUT_ROOT and skill_path, but it does not declare any explicit tool scope or allowed-tools restrictions. In an agentic environment, missing scope boundaries can let the skill run with broader-than-necessary capabilities, increasing the blast radius if the skill is misused or later modified to access sensitive environment data or invoke unintended tools.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code rewrites the workbook in place without any user-facing warning, confirmation, backup, or transactional safeguard. In this skill's context, users may supply spreadsheets for inspection or repair, so silent modification is more dangerous because it can overwrite originals, interfere with forensic review, or corrupt business data if the write path is unexpected or partially fails.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The helper explicitly states it modifies the XLSX in place by injecting cached formula values, while the surrounding framing presents the operation as recalculation/analysis. In an agent skill context, this hidden write side effect can unexpectedly alter user files, violate read-only expectations, and permanently change workbook contents or metadata if the file is later saved or trusted as original.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The public recalc API is documented as a scan that returns status and error summaries, but it also rewrites the provided Excel file through cached-value injection. That mismatch is security-relevant because callers may invoke it on sensitive or canonical documents expecting inspection only, causing silent integrity changes and possible downstream trust issues.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.