Back to skill

Security audit

Csv Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward CSV analysis skill with some documentation and hardening gaps, but no hidden persistence, credential access, network behavior, or deceptive payloads were found.

Install only if you want a lightweight CSV-only CLI helper. Do not rely on the advertised Excel or natural-language support, avoid exporting over important files, and be careful opening exported CSVs from untrusted input in spreadsheet applications because formulas are not neutralized.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/csv_analyze.py:101
Finding

Spreadsheet Formula Injection in Exported CSV Files

Content
View full analysis
1000" --output result.csv ``` 3. The malicious row satisfies the filter condition. 4. `writerows(filtered)` copies the malicious cell unchanged into `result.csv`. 5. The user opens `result.csv` in spreadsheet software. 6. Depending on the spreadsheet application and its security configuration, the formula may execute automatically or after a security prompt. ### Impact Assessment Exploitation occurs in the security context of the user who opens the exported CSV, rather than during execution of the Python script itself. Depending on spreadsheet capabilities and security settings, a malicious formula could: - Initiate external network requests and disclose data embedded in the spreadsheet. - Display deceptive or attacker-controlled content. - Invoke dangerous spreadsheet features or external programs where leg ...[truncated 307 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code substantially matches the general idea of lightweight CSV analysis using only the Python standard library, including statistics, row filtering, anomaly detection, grouping/aggregation, and optional export of filtered results. However, the declared description overstates capabilities in several material ways: the implementation only reads CSV, not Excel; it is not a natural-language interface but a strict argparse CLI with structured commands; and 'generate summaries' is only partially represented by basic stats/group text output rather than a broader summarization capability. There are no undeclared dangerous behaviors or extra permissions/resource accesses apparent in this chunk. The main mismatch is overclaiming supported formats and interface style.

Content

No source excerpt is available for this finding.

eval() call detected

High
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

Direct eval() call evaluates arbitrary expressions. This can be exploited to execute malicious code or exfiltrate data.

Content

Scanner excerpt · scripts/csv_analyze.py (reported line 95)May include surrounding context.

python
def matches(row_val):
        if is_numeric(row_val) and is_numeric(val):
            a, b = float(row_val), float(val)
            return eval(f"a {op} b")
        else:
            if op == "==": return row_val.strip() == val
            if op == "!=": return row_val.strip() != val

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises file export behavior and static analysis detected file-write capability, but the manifest does not declare any explicit tool scope or permissions. This weakens review and containment because an agent may invoke write-capable behavior without clear upfront authorization boundaries, increasing the risk of unintended file modification or overwrite.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest description promises analysis of both CSV and Excel files, but the implementation only uses Python's csv module to open a single text file path and parse it as CSV. There is no code for reading .xlsx/.xls formats or any Excel-specific handling, so the documented capability overstates actual behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

A CSV analysis tool only needs simple comparison logic to filter rows, but this implementation invokes Python eval on a constructed expression. Even though the operator is regex-constrained, introducing dynamic code evaluation is a capability beyond what is needed for the stated purpose and increases risk relative to a straightforward comparator implementation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The filter subcommand can create or overwrite a user-specified output file, which is a file-write operation covered by this rule. Although it prints after saving, the script's docstring and argument descriptions do not warn users in advance that running this command may modify the filesystem.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/csv_analyze.py:95