csv-formula-injection

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as a CSV formula injection testing guide, but it gives an AI agent concrete exploit payloads for local command execution and outbound data exfiltration. There is no installer or credential harvesting path, so this is high-risk offensive guidance rather than confirmed malware.

Confidence: 95%Severity: 84%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:25 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fcsv-formula-injection%2F@c8b18988fcbe5ba267bb032a525d0a6fbbabc67e98f527d65c6783e083e0c3ed
Security Audit — socket — csv-formula-injection