Back to skill

Security audit

excel-parser

Security checks for vulnerabilities and agentic risk

Overview

The skill is an Excel parser, but it can automatically download and install unpinned Python packages during normal use, which should be reviewed before installation.

Install only in an isolated environment where runtime package installation cannot affect shared projects, or require dependencies to be preinstalled from pinned, reviewed versions. Treat the automatic pip-install behavior as the main review item; no artifact-backed evidence of data theft or destructive behavior was found.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/excel_parser.py:17
Finding

Automatic Runtime Installation of Unpinned Third-Party Packages

Content
View full analysis

Vulnerability Details

File Location: scripts/excel_parser.py:17-27, with invocation at scripts/excel_parser.py:41-52
Vulnerability Type: Unsafe runtime dependency installation and supply-chain exposure
Risk Level: Medium

Complete Code Snippet

python
def install_dependency(package):
    """Automatically install a missing dependency."""
    import subprocess
    print(f"Installing dependency: {package}")
    try:
        subprocess.check_call(
            [sys.executable, "-m", "pip", "install", package]
        )
        print(f"Dependency {package} installed successfully")
        return True
    except subprocess.CalledProcessError as e:
        print(f"Dependency {package} installation failed: {e}")
        return False

The installation routine is invoked automatically while initializing the parser:

python
def _init_engine(self):
    """Initialize the parsing engine."""
    try:
        from python_calamine import CalamineWorkbook
        self.calamine = CalamineWorkbook
    except ImportError:
        print("Calamine dependency is not installed; attempting automatic installation...")
        if install_dependency("python-calamine"):
            try:
                from python_calamine import CalamineWorkbook
                self.calamine = CalamineWorkbook
            except ImportError:
                raise Exception(
                    "Calamine dependency installation failed; "
                    "install it manually with: pip install python-calamine"
                )
        else:
            raise Exception(
                "Calamine dependency installation failed; "
                "install it manually with: pip install python-calamine"
            )

The primary dependencies are also unconstrained:

text
python-dotenv
python-calamine

Technical Analysis

Constructing an ExcelParser object can launch pip and modify the active Python environment without a separate installation or deployment deci ...[truncated 2634 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove runtime installation

    • Do not invoke pip from parsing or library initialization code.
    • Raise a clear ImportError that identifies the missing optional dependency and the explicit installation command.
  2. Install dependencies during controlled deployment

    • Resolve and install packages in a dedicated build or deployment stage.
    • Run the Skill in an isolated virtual environment or container with read-only application dependencies where practical.
  3. Pin reviewed versions

    • Use exact, reviewed versions in a lock or constraints file.
    • Pin both direct and transitive dependencies.
    • Review dependency updates before deployment rather than resolving the newest release during execution.
  4. Verify package artifacts

    • Use a hash-locked requirements file and install with pip install --require-hashes.
    • Prefer an approved internal package mirror containing reviewed artifacts.
  5. Declare fallback packages explicitly

    • If xlrd and openpyxl are supported runtime dependencies, declare them as pinned optional extras instead of installing them on demand.
    • For example, provide an excel-parser-skill[fallback] extra that administrators install explicitly.
  6. Apply least privilege and network controls

    • Run the parser as an unprivileged account.
    • Prevent ordinary parsing workloads from writing to shared Python environments.
    • Deny outbound package-index access at runtime when it is unnecessary.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (29)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 33)May include surrounding context.

text
.idea/

# Environment variables
.env

# Test files
test/

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Automatically installing packages is not necessary for Excel content extraction and materially expands the skill's behavior beyond parsing. This can introduce remote code execution through package installation hooks, dependency confusion, or compromised upstream packages, making the skill dangerous in automated agent environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill documentation uses Chinese throughout, but there is no indication that the skill is region-specific or that users can choose a preferred language. This can violate language/locale policy expectations when a skill implicitly forces one language without opt-in or justification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly advertises automatic dependency installation, which implies the skill may modify the runtime environment and invoke package installation beyond the user's direct Excel-parsing request. In agent or sandboxed environments, auto-install behavior can expand attack surface, introduce unreviewed code from package registries, and violate least-privilege expectations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises code-adjacent capabilities in its documentation and usage examples, including environment configuration, file access, and Python execution context, but does not declare any explicit tool scope or permission boundaries. In an agent system, this can cause the skill to be invoked with broader runtime capabilities than users expect, increasing the chance of unintended file access or shell-assisted processing without clear policy enforcement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation description says the skill must be used whenever a user needs to parse, analyze, convert, or batch-process Excel files, which is overly broad and directive. This can lead to over-triggering on ordinary spreadsheet-related requests, causing unnecessary file handling or automated processing in contexts where a safer or narrower response would suffice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill metadata and description are written in Chinese and strongly prescribe behavior in that locale without any indication that language selection follows user preference. In multi-lingual agent environments, hard-coded language behavior can confuse users, misroute requests, or cause the agent to apply the skill inappropriately when the user did not opt into Chinese-language handling.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The code imports load_dotenv() and loads environment variables globally, but the rest of the skill only parses local Excel files and does not use environment-based configuration. Accessing ambient environment configuration is not justified by the manifest's narrow file-parsing purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Running pip automatically without explicit user or administrator consent is unsafe, particularly in a background skill context where execution may be triggered indirectly. It can result in unreviewed code download and execution, violating the principle of least astonishment and exposing the host to supply-chain compromise.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
97% confidence
Finding

The script invokes pip at runtime via subprocess, which changes the execution environment and can fetch and execute code from package indexes without prior approval. In an agent skill whose stated purpose is only to parse Excel files, this creates unnecessary supply-chain and arbitrary code execution risk if dependency sources are compromised or if invocation occurs in sensitive environments.

Content

Scanner excerpt · scripts/excel_parser.py (reported line 22)May include surrounding context.

python
import subprocess
    print(f"正在安装依赖: {package}")
    try:
        subprocess.check_call([sys.executable, "-m", "pip", "install", package])
        print(f"依赖 {package} 安装成功")
        return True
    except subprocess.CalledProcessError as e:

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The implementation exceeds the advertised calamine-only parsing behavior by adding fallback engines and environment-modifying setup logic. This mismatch increases attack surface and makes the skill less predictable for operators, especially because fallback paths can trigger package installation and additional parser code paths on untrusted files.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The guide instructs users to run npx skills add without pinning an exact package/version, which allows whatever current version of the referenced installer path resolves at execution time to run. This creates a supply-chain risk: a compromised upstream package, changed dependency, or malicious repo state could cause users or CI systems to execute unintended code during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This installation example uses npx skills add with an unpinned GitHub source, so the code fetched and executed can change over time without the user's awareness. If the repository, release target, or toolchain is compromised, consumers may install and run attacker-controlled content.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using the full GitHub URL still does not pin the installed skill to a specific immutable version, so users may retrieve different content over time. This is particularly risky because installation tooling often executes package logic, making a repo compromise or force-pushed change a practical supply-chain attack vector.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The command for installing only the excel-parser skill still relies on an unpinned upstream source, so narrowing the skill selection does not reduce the supply-chain exposure. An attacker controlling the repository or dependency chain could still deliver malicious installation content.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The --global example is more dangerous because it installs from an unpinned source into a broader trust scope on the user's system. If compromised content is fetched, the resulting impact can persist across projects and affect more workflows than a local install.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The non-interactive --yes CI/CD example combines unpinned remote installation with suppressed confirmation, increasing the chance of automated compromise. In CI, such a supply-chain issue can expose secrets, tamper with build outputs, or propagate malicious artifacts downstream without human review.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The release verification section repeats the unpinned npx skills add install command, reinforcing unsafe installation practices. Even as a test step, executing an unversioned remote installer can run altered code if the upstream source changes or is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The changelog content is written entirely in Chinese and links to Chinese-localized documentation, which indicates a fixed language choice. There is no surrounding note offering language choice or explaining a region-specific requirement, so this can conflict with organizational language/locale choice policies.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Describing automatic dependency installation without warning that it changes the host environment is a security transparency issue. Users and operators may invoke a file-parsing skill expecting read-only behavior, but the skill may instead perform network/package-management actions that alter the system state.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency python-dotenv is unpinned, so installs may resolve to different versions over time, including versions with undisclosed regressions or known security issues. In a file-processing skill, this weakens build reproducibility and makes it harder to ensure vulnerable releases are not pulled into production.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
python-dotenv
python-calamine

Static analysis

No suspicious patterns detected.