csv-formula-injection
Warn
Audited by Socket on Jul 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent as a CSV formula injection testing guide, but it gives an AI agent concrete exploit payloads for local command execution and outbound data exfiltration. There is no installer or credential harvesting path, so this is high-risk offensive guidance rather than confirmed malware.
Confidence: 95%Severity: 84%
Audit Metadata