T09 · Insecure Skill Coding Practices
- Location
scripts/generate_workflow_blueprint.py:55- Finding
Spreadsheet Formula Injection in CSV Output
- Content
View full analysis
- Remediation
View remediation
str: text = str(value) if text.startswith(("=", "+", "-", "@")): return "'" + text return text ``` Apply the function when normalizing or immediately before writing CSV rows: ```python safe_steps = [ { "order": step["order"], "name": sanitize_csv_cell(step["name"]), "type": sanitize_csv_cell(step["type"]), "on_failure": sanitize_csv_cell(step["on_failure"]), } for step in result["details"]["steps"] ] writer.writerows(safe_steps) ``` Additional hardening measures: 1. Apply formula neutralization only to CSV output so that JSON and Markdown retain their original values. 2. Document that imported workflow fields are untrusted. 3. Add tests covering values beginning with each formula marker. 4. Test the resulting CSV files with the spreadsheet applications expected in the deployment environment. 5. Do not rely on CSV quoting alone, because quoting does not reliably disable spreadsheet formula interpretation. ]]>
