T09 · Insecure Skill Coding Practices
- Location
merge_script.py:185- Finding
Spreadsheet Formula Injection Through Unsanitized Workbook Values
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Excel merge skill is mostly a straightforward local workbook utility, but it can copy attacker-controlled spreadsheet formulas into its generated output workbook.
Review before installing if you may process workbooks from untrusted parties. The skill should sanitize names and specifications that begin with =, +, -, @, tab, carriage return, or newline before writing the output workbook. For trusted internal spreadsheets, the core behavior is coherent and local-only.
merge_script.py:185Spreadsheet Formula Injection Through Unsanitized Workbook Values
L223-L227 的示例在调用 merge_excel_tables 后打印 len(data_dict),但 data_dict 是函数内部局部变量,主程序作用域中并不存在,因此该示例无法按注释意图工作。文档将其展示为可直接运行的“使用示例”,这与代码真实行为形成直接矛盾。
This code contains natural-language comments, worksheet titles, headers, and user-facing print messages exclusively in Chinese. Under the policy rule, forcing a specific language without user opt-in or a documented locale justification is a natural-language policy violation.
No suspicious patterns detected.