csv-formula-injection

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a documentation resource for security professionals to test for CSV injection vulnerabilities.
  • [PROMPT_INJECTION]: No malicious instructions designed to bypass agent safety filters were detected. The skill includes standard security warnings regarding authorization.
  • [DATA_EXFILTRATION]: Mentions of data exfiltration methods (like Google Sheets IMPORTXML) are strictly for educational purposes and testing spreadsheet software behaviors.
  • [REMOTE_CODE_EXECUTION]: Example payloads for DDE injection (e.g., cmd|' /C calc') are provided for security research and are not executed by the AI agent during normal operation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 01:23 PM
Security Audit — agent-trust-hub — csv-formula-injection