csv-formula-injection

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. This skill is internally consistent as a CSV formula-injection testing guide and shows no supply-chain, credential-harvesting, or hidden exfiltration by the skill itself. However, it equips an AI agent with concrete offensive payloads, obfuscation methods, and exfiltration primitives, creating high security risk even with authorization caveats.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:13 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fcsv-formula-injection%2F@c8b18988fcbe5ba267bb032a525d0a6fbbabc67e98f527d65c6783e083e0c3ed
Security Audit — socket — csv-formula-injection