T09 · Insecure Skill Coding Practices
- Location
SKILL.md:161- Finding
Spreadsheet Formula Injection in CSV Exports
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:161-174andSKILL.md:208-214
Vulnerability Type: CSV/spreadsheet formula injection
Risk Level: MediumVulnerable Code
python def split_csv(self, df: pd.DataFrame, group_column: str, output_dir: str) -> List[str]: """Split CSV by column values.""" output_path = Path(output_dir) output_path.mkdir(parents=True, exist_ok=True) files = [] for value in df[group_column].unique(): subset = df[df[group_column] == value] filename = f"{group_column}_{value}.csv" filepath = output_path / filename subset.to_csv(filepath, index=False) files.append(str(filepath)) return filespython def export_csv(self, df: pd.DataFrame, file_path: str, encoding: str = 'utf-8-sig', delimiter: str = ',') -> str: """Export DataFrame to CSV.""" df.to_csv(file_path, encoding=encoding, sep=delimiter, index=False) return file_pathTechnical Analysis
The export methods write DataFrame cell values directly to CSV without neutralizing spreadsheet formula prefixes. Values beginning with
=,+,-, or@may be interpreted as formulas when a generated file is opened in spreadsheet software.CSV quoting does not reliably prevent formula evaluation because spreadsheet applications commonly evaluate quoted fields after parsing them. An attacker able to influence source construction data could therefore place formula content in fields such as task names, resource names, cost descriptions, or comments. The cleaning routine strips whitespace but does not identify or escape formulas, so the payload can survive reading, cleaning, merging, splitting, and exporting.
Attack Path
- An attacker supplies or modifies a construction CSV containing a value such as `=HYPERLINK("https://attacker.example", ...[truncated 1031 chars]
- Remediation
View remediation
Remediation Suggestions
- Sanitize string cells before any spreadsheet-oriented CSV export.
- Prefix values whose first non-whitespace character is
=,+,-, or@with an apostrophe or another application-approved neutralization character. - Apply sanitization consistently in both
split_csvandexport_csv. - Consider treating tab, carriage-return, and line-feed prefixes as dangerous because spreadsheet parsing behavior varies.
- Keep raw export behavior disabled by default. If exact value preservation is required, expose it as an explicit option with a security warning.
- Add automated tests covering dangerous prefixes, quoted formulas, leading whitespace, embedded newlines, and values imported from merged files.
- Document that CSV files intended for spreadsheet use must not be trusted merely because fields are quoted.
