Back to skill

Security audit

Unit Price Database Manager

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent construction pricing helper with expected local CSV import/export behavior, but users should handle CSV files and dependencies carefully.

Install in an isolated environment, preferably with a pinned pandas version. Import CSVs only from trusted sources, choose export paths deliberately to avoid overwriting files, and sanitize text fields that may start with spreadsheet formula characters before sharing or opening exported CSVs in spreadsheet applications.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:339
Finding

Spreadsheet Formula Injection in CSV Exports

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 339-360
Vulnerability Type: CSV/spreadsheet formula injection
Risk Level: Medium

Vulnerable Code

python
data.append({
    'code': price.code,
    'description': price.description,
    'unit': price.unit,
    'base_price': float(price.base_price),
    'labor_cost': float(price.labor_cost),
    'material_cost': float(price.material_cost),
    'equipment_cost': float(price.equipment_cost),
    'location': price.location,
    'effective_date': price.effective_date.isoformat(),
    'source': price.source,
    'tags': ','.join(price.tags)
})

df = pd.DataFrame(data)
df.to_csv(file_path, index=False)
return len(data)

Technical Analysis

The CSV export writes user-controlled textual fields, including item codes, descriptions, units, locations, sources, and tags, without neutralizing spreadsheet formula prefixes. Spreadsheet applications may interpret cells beginning with characters such as =, +, -, or @ as formulas rather than plain text.

CSV quoting performed by pandas does not neutralize formulas because spreadsheet applications generally evaluate a quoted CSV cell after parsing it. An attacker able to introduce a crafted value into an imported or manually created price record can therefore cause dangerous spreadsheet content to be emitted during export.

For example, a malicious description or source could contain a formula that references external resources or attempts to transmit spreadsheet data when the exported file is opened. Actual behavior depends on the spreadsheet application, its version, and its security configuration.

Attack Path

  1. An attacker supplies a price record containing a formula-prefixed value in a textual field such as description, source, or tags.
  2. The record is imported from CSV or added to the in-memory price database.
  3. A user invokes export_to_csv.
  4. The untrusted value is written to the output CSV without formula neutraliz ...[truncated 952 chars]
Remediation
View remediation

Remediation Suggestions

Apply a centralized spreadsheet-safe escaping function to every textual field before writing CSV output.

python
def sanitize_spreadsheet_cell(value):
    if value is None:
        return value

    text = str(value)
    if text.lstrip().startswith(("=", "+", "-", "@")):
        return "'" + text
    return text

Use the function on code, description, unit, location, source, and each tag before constructing the DataFrame. Consider treating tab, carriage-return, and line-feed prefixes as dangerous where spreadsheet compatibility requires it.

Additional hardening should include:

  • Validate imported and manually supplied fields at the trust boundary.
  • Provide an export mode that forces all textual values to remain text.
  • Document that exported files may contain untrusted data.
  • Add tests covering formula prefixes, leading whitespace, tabs, newlines, and quoted values.
  • If spreadsheet interoperability permits it, export to a format with explicit text cell types rather than CSV.

T08 · Insecure Dependencies

Note
Location
SKILL.md:490
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 490-494
Vulnerability Type: Mutable and non-reproducible dependency installation
Risk Level: Low

Vulnerable Code

bash
pip install pandas

Technical Analysis

The documented installation command does not pin a reviewed pandas version, constrain transitive dependencies, or verify package hashes. Consequently, installations performed at different times can resolve to different package and dependency versions.

The package name shown is the legitimate pandas package, and the audited content does not specify an untrusted package index or demonstrate dependency confusion. The risk arises from mutable dependency resolution: a future compromised, malicious, or incompatible release could be installed automatically without another review of this Skill.

Attack Path

  1. A user follows the dependency installation instructions.
  2. pip queries the configured Python package index and resolves the latest compatible pandas release and its transitive dependencies.
  3. No lock file or hash verification confirms that the resolved artifacts match versions reviewed by the project.
  4. If an upstream release, transitive dependency, configured index, or distribution artifact is compromised, malicious package behavior may execute during installation or later import.
  5. The malicious dependency executes with the privileges of the user or environment running pip or the Skill.

Impact Assessment

A compromised dependency could execute arbitrary Python behavior within the installation or runtime environment. Its practical privileges would be those of the account running the installation or importing the package, potentially including access to project files, environment variables, credentials available to that account, and network resources.

There is no evidence in the audited files that pandas is currently compromised. This finding concerns supply-chain hardening and the absence of reprodu ...[truncated 26 chars]

Remediation
View remediation

Remediation Suggestions

Replace the unconstrained installation instruction with a reproducible dependency-management process:

  • Pin a tested pandas version in a requirements or lock file.
  • Pin transitive dependencies through a generated lock file.
  • Use package hashes, such as pip's --require-hashes, to verify artifacts.
  • Retrieve packages only from an explicitly approved index.
  • Review and update pins through a controlled dependency-update process.
  • Run dependency vulnerability and provenance checks in CI.
  • Install dependencies in an isolated virtual environment with minimal privileges.

For example:

text
pandas==<reviewed-version> --hash=sha256:<verified-wheel-hash>

The exact version and hash should be selected from a tested, reviewed release rather than copied from an unverified source.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file embeds code that reads from a CSV path and writes to a CSV path, which can affect local user data. While the methods have brief docstrings, the skill description and surrounding markdown do not warn users that importing will read local files and exporting may overwrite an existing file at the provided path.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.