T09 · Insecure Skill Coding Practices
- Location
scripts/get_data.py:320- Finding
CSV Formula Injection in Exported Screening Results
- Content
View full analysis
Vulnerability Details
File Location:
scripts/get_data.py, lines 320-323
Vulnerability Type: CSV formula injection caused by unsanitized remote data
Risk Level: MediumVulnerable Code
python with open(csv_path, "w", newline="", encoding="utf-8") as f: writer = csv.DictWriter(f, fieldnames=fieldnames, extrasaction="ignore") writer.writeheader() for row in rows: writer.writerow(row)Technical Analysis
The application writes column names and values derived from the remote MCP response directly to a CSV file. It does not neutralize strings beginning with spreadsheet formula indicators such as
=,+,-, or@. Leading tab or carriage-return characters can also be used to conceal formula prefixes from simplistic validation.CSV quoting performed by
csv.DictWriterdoes not prevent Microsoft Excel or another spreadsheet application from interpreting a cell as a formula. The documentation explicitly states that generated CSV files can be opened with Excel, making spreadsheet evaluation part of the expected usage.An attacker able to influence the East Money API response, including through compromise of the remote service or its upstream data, could return a value such as a formula that initiates an external request when the CSV is opened. The same issue applies to remotely derived column headers because
writer.writeheader()writes them without sanitization.Attack Path
- An attacker gains the ability to influence a value or column name returned by the configured MCP endpoint.
- The attacker supplies content beginning with a spreadsheet formula prefix.
_datalist_to_rowsconverts the value to a string without neutralizing formula syntax.csv.DictWriterwrites the attacker-controlled content unchanged into the generated CSV file.- The user opens the CSV file in Excel or another formula-evaluating spreadsheet application.
- The spreadsheet inter ...[truncated 931 chars]
- Remediation
View remediation
Remediation Suggestions
Sanitize every remotely derived CSV value and header before writing it:
- Treat values as potentially dangerous if, after applicable normalization, they begin with
=,+,-,@, tab, or carriage return. - Prefix dangerous values with an apostrophe or another spreadsheet-compatible text marker.
- Apply the same protection to
fieldnamesbefore callingwriteheader(). - Preserve the original untrusted value separately only if required; do not place it directly in formula-evaluating cells.
- Consider generating a spreadsheet format that supports explicit text cell types rather than relying on CSV.
- Document that exported data is untrusted and should not be opened with formula execution enabled.
- Add tests covering malicious headers and values beginning with
=,+,-,@, tab, and carriage return. - Test values containing leading whitespace or control characters to ensure normalization cannot bypass the protection.
A centralized sanitizer should be applied immediately before CSV serialization so that both
dataListandpartialResultsoutput paths receive identical protection.- Treat values as potentially dangerous if, after applicable normalization, they begin with
