T09 · Insecure Skill Coding Practices
- Location
scripts/invoice_export.py:55- Finding
CSV Formula Injection in Invoice Exports
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a review-first local Shopify reporting helper, but its CSV exports should be handled carefully because spreadsheet formula escaping is missing.
Install only if you are comfortable using it as a local, review-first helper for Shopify exports. Treat generated CSV files as untrusted business data: inspect inputs, avoid opening exports with formula execution enabled, and consider adding spreadsheet-safe escaping before using the scripts for customer-controlled order or product data.
scripts/invoice_export.py:55CSV Formula Injection in Invoice Exports
scripts/stock_sync.py:83CSV Formula Injection in Stock Reconciliation Exports
scripts/monthly_ops_report.py:57CSV Formula Injection Through SKU Values in Monthly Reports
scripts/monthly_ops_report.py:51Malformed Quantity Causes Monthly Report Generation to Fail
The skill advertises broad Shopify workflow capabilities, but the described/bundled behavior appears limited to local file transformation and reporting helpers. This mismatch can mislead operators into trusting the skill to perform order detection, inventory reconciliation, or monthly reporting correctly when those controls may not actually exist, increasing the chance of incorrect financial or stock actions.
Without declared permissions the skill's intent is opaque and cannot be validated.
No suspicious patterns detected.