Back to skill

Security audit

Excel Master

Security checks for vulnerabilities and agentic risk

Overview

This Excel skill is mostly purpose-aligned, but it can read and overwrite spreadsheet files and relies on an undeclared runtime dependency despite claiming it is dependency-free.

Install only if you are comfortable letting the skill open spreadsheet files you name and overwrite the currently opened workbook when you ask it to save. The package should be fixed to declare and pin xlsx, and users should keep backups of important spreadsheets until save behavior is documented and guarded.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
index.js:1
Finding

Undeclared and Unpinned Third-Party Runtime Dependency

Content
View full analysis

Vulnerability Details

File Location: index.js:1 and package.json:1-6
Vulnerability Type: Undeclared third-party dependency and uncontrolled module resolution
Risk Level: Medium

Vulnerable Code

index.js:1:

js
const XLSX = require("xlsx");

package.json:1-6:

json
{
  "name": "excel-master",
  "version": "1.0.1",
  "main": "index.js",
  "dependencies": {}
}

Technical Analysis

The skill requires the third-party xlsx module at runtime, but the package manifest declares no dependencies and therefore does not constrain the module's source, version, or integrity. Node.js will search its module-resolution paths for an ambient copy of xlsx. Consequently, the code may load a host-provided or locally shadowed package that was not included in this audit.

Because a Node.js module executes initialization code immediately when loaded through require, a malicious replacement can run arbitrary JavaScript before any workbook operation occurs. Exploitation requires an attacker or compromised installation process to control a directory searched by Node.js, such as a relevant node_modules/xlsx path. If no ambient module exists, the immediate result is an availability failure rather than code execution.

Attack Path

  1. An attacker gains write access to a node_modules directory searched when index.js resolves xlsx, or influences the deployment process to install an untrusted package under that name.
  2. The attacker places a malicious xlsx package in that resolution path.
  3. The host loads the skill and executes require("xlsx").
  4. Node.js resolves and initializes the attacker-controlled module.
  5. The malicious module executes with the same operating-system identity and permissions as the agent process.

Impact Assessment

Successful exploitation permits arbitrary JavaScript execution within the skill host process. The attacker could access files and en ...[truncated 352 chars]

Remediation
View remediation

Remediation Suggestions

  1. Add xlsx to package.json under dependencies using a deliberately selected and audited version.
  2. Generate and commit a package-manager lockfile containing resolved versions and integrity hashes.
  3. Install dependencies only from a trusted registry and use deterministic installation commands such as npm ci.
  4. Apply registry allowlisting, lockfile validation, and dependency scanning in the build and release pipeline.
  5. Ensure application and ancestor node_modules directories are not writable by untrusted users.
  6. Review the selected package version for known vulnerabilities before release and maintain a controlled update process.
  7. Correct documentation claiming that the skill runs without dependencies, because its implementation requires xlsx.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

All user-facing descriptive and usage text is presented only in Chinese, with no indication that another language can be used or selected. This can constitute a language/locale policy violation when the skill appears to require a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The usage example '打开excel 文件路径.xlsx' is a broad natural-language trigger that can overlap with ordinary user requests to open a spreadsheet. In an agent skill system, ambiguous activation increases the chance of unintended invocation and file access actions without the user clearly intending to call this specific skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises save and PDF export capabilities, which can modify existing files or create new files on the user's system, but it provides no warning, confirmation requirement, or scope limitation. In an agent setting, undocumented write behavior increases the risk of unintended data alteration, overwriting files, or leaving sensitive derivative artifacts such as exported PDFs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill writes the workbook back to the current file path immediately when the command includes '保存', with no confirmation, backup, alternate output path, or overwrite protection. In an agent context, this can cause unintended destructive changes or data loss if the user did not explicitly intend to overwrite the source spreadsheet or if a prior command modified workbook state unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The README advertises opening Excel files and performing processing/export operations but does not warn that these actions may read, modify, or create user files. That omission can lead users to invoke the skill without understanding filesystem side effects, increasing the risk of accidental data changes or unintended exports.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

All user-facing natural language in the skill is presented in Chinese, and the description does not state that language is configurable or limited to a Chinese-speaking context. This can violate language/locale policy when a skill implicitly enforces one language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language interface for the skill, including description text and all trigger phrases, is fixed to Chinese. This can violate language/locale policy when no user opt-in, alternative language support, or justification for the locale restriction is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.