csv-formula-injection
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions as a documentation resource for security professionals to test for CSV injection vulnerabilities.
- [PROMPT_INJECTION]: No malicious instructions designed to bypass agent safety filters were detected. The skill includes standard security warnings regarding authorization.
- [DATA_EXFILTRATION]: Mentions of data exfiltration methods (like Google Sheets IMPORTXML) are strictly for educational purposes and testing spreadsheet software behaviors.
- [REMOTE_CODE_EXECUTION]: Example payloads for DDE injection (e.g., cmd|' /C calc') are provided for security research and are not executed by the AI agent during normal operation.
Audit Metadata