T09 · Insecure Skill Coding Practices
- Location
SKILL.md:339- Finding
Spreadsheet Formula Injection in CSV Exports
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 339-360
Vulnerability Type: CSV/spreadsheet formula injection
Risk Level: MediumVulnerable Code
python data.append({ 'code': price.code, 'description': price.description, 'unit': price.unit, 'base_price': float(price.base_price), 'labor_cost': float(price.labor_cost), 'material_cost': float(price.material_cost), 'equipment_cost': float(price.equipment_cost), 'location': price.location, 'effective_date': price.effective_date.isoformat(), 'source': price.source, 'tags': ','.join(price.tags) }) df = pd.DataFrame(data) df.to_csv(file_path, index=False) return len(data)Technical Analysis
The CSV export writes user-controlled textual fields, including item codes, descriptions, units, locations, sources, and tags, without neutralizing spreadsheet formula prefixes. Spreadsheet applications may interpret cells beginning with characters such as
=,+,-, or@as formulas rather than plain text.CSV quoting performed by pandas does not neutralize formulas because spreadsheet applications generally evaluate a quoted CSV cell after parsing it. An attacker able to introduce a crafted value into an imported or manually created price record can therefore cause dangerous spreadsheet content to be emitted during export.
For example, a malicious description or source could contain a formula that references external resources or attempts to transmit spreadsheet data when the exported file is opened. Actual behavior depends on the spreadsheet application, its version, and its security configuration.
Attack Path
- An attacker supplies a price record containing a formula-prefixed value in a textual field such as
description,source, ortags. - The record is imported from CSV or added to the in-memory price database.
- A user invokes
export_to_csv. - The untrusted value is written to the output CSV without formula neutraliz ...[truncated 952 chars]
- An attacker supplies a price record containing a formula-prefixed value in a textual field such as
- Remediation
View remediation
Remediation Suggestions
Apply a centralized spreadsheet-safe escaping function to every textual field before writing CSV output.
python def sanitize_spreadsheet_cell(value): if value is None: return value text = str(value) if text.lstrip().startswith(("=", "+", "-", "@")): return "'" + text return textUse the function on
code,description,unit,location,source, and each tag before constructing the DataFrame. Consider treating tab, carriage-return, and line-feed prefixes as dangerous where spreadsheet compatibility requires it.Additional hardening should include:
- Validate imported and manually supplied fields at the trust boundary.
- Provide an export mode that forces all textual values to remain text.
- Document that exported files may contain untrusted data.
- Add tests covering formula prefixes, leading whitespace, tabs, newlines, and quoted values.
- If spreadsheet interoperability permits it, export to a format with explicit text cell types rather than CSV.
