T09 · Insecure Skill Coding Practices
- Location
scripts/ms_financial_model.py:474- Finding
Excel Formula Injection Through Unsanitized Model Text
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent Excel financial-model generator, but it can write untrusted input into spreadsheets as executable formulas and includes a misleading margin chart calculation.
Install only if you control and trust the input data, or sanitize text fields before generating and sharing workbooks. Treat generated margin charts as potentially approximate and review formulas before using the workbook for investment or valuation decisions.
scripts/ms_financial_model.py:474Excel Formula Injection Through Unsanitized Model Text
Suspicious Unicode normalization or mixed-script content
The skill description is broadly scoped to many common finance requests such as financial modeling, DCF, SOTP, sensitivity, PE band, and comparables analysis. Overly broad invocation criteria can cause the agent to trigger this skill in situations where it is unnecessary or where user data should not be routed into complex spreadsheet-generation workflows, increasing the attack surface for prompt injection, unintended file generation, or mishandling of sensitive financial inputs.
Suspicious Unicode normalization or mixed-script content
The code sets Chinese as the default language in both helper logic and the CLI (language: str = "zh", default="zh"), which forces a specific locale unless the user explicitly overrides it. This is a natural-language locale policy concern because the default behavior does not first offer or infer a language choice from the user.
The chart helper claims to present Gross Margin and Net Margin, but when those rows do not exist it silently fabricates proxy metrics from EBIT/Revenue and NOPAT/Revenue. In a financial modeling skill, this can mislead users into trusting materially incorrect outputs, which is dangerous because the generated workbook is meant to support valuation and investment analysis.
The usage examples hard-code language="zh" and --lang zh, which presents a specific language choice as the default invocation. Under the policy, forcing a language/locale without explicit user opt-in is a natural-language policy concern, and the README does not offer a neutral default or call out this as an optional example choice.
No suspicious patterns detected.