T09 · Insecure Skill Coding Practices
- Location
scripts/manager.py:359- Finding
CSV Formula Injection Through Unescaped Subscription Fields
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent local subscription tracker, but its cancellation wording may mislead users into thinking real paid subscriptions are cancelled when only local records are changed.
Install only if you understand this manages a local tracker, not your actual accounts. Treat 'cancel' as 'mark cancelled/remove from my records' and separately cancel with the provider. Be careful opening CSV exports in spreadsheets if subscription names, notes, or URLs came from untrusted text.
scripts/manager.py:359CSV Formula Injection Through Unescaped Subscription Fields
The README presents commands and natural-language examples like 'Cancel my Hulu subscription' and 'python scripts/manager.py remove --name "Netflix"' without clearly stating that these actions only remove the local tracking entry and do not cancel the real subscription with the provider. In a financial-management skill, this can mislead users into believing a paid service has been terminated, causing continued billing, missed renewals, and financial loss.
The skill advertises file-backed functionality and explicitly references local JSON storage plus a required script, but it declares no tool scope or allowed-tools constraints. In an agent environment, that means the skill can end up with broader file read/write capability than users or reviewers expect, increasing the chance of unintended modification or exposure of local data.
The invocation triggers are broad enough to activate on general budgeting, service-cost, or cancellation conversations, not just clear subscription-management requests. Over-broad auto-invocation can cause the agent to read or write subscription data in contexts where the user did not intend to use this skill, creating privacy and integrity risks through mistaken activation.
The primary command trigger "track subscriptions" is relatively generic and does not encode any explicit scoping or confirmation requirements, which can cause the skill to activate in unintended contexts. In a finance-related skill, accidental activation can expose or process sensitive spending and subscription data when the user did not intend to invoke this capability.
This code path removes a subscription from the stored dataset and writes the change back to disk immediately when --permanent is used. Although it prints a message after deletion, there is no prior confirmation prompt or explicit warning at the point of execution for this irreversible local data loss operation.
No suspicious patterns detected.