csv-formula-injection
Warn
Audited by Socket on Apr 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
This skill is coherent with its stated purpose, but that purpose is to teach offensive spreadsheet-exploitation techniques. It does not show malware-like installation, credential harvesting, or hidden exfiltration by the skill itself, yet it materially enables command-execution and outbound-request abuse against target spreadsheet workflows. Final classification: SUSPICIOUS / high-risk offensive security skill, not confirmed malware.
Confidence: 92%Severity: 76%
Audit Metadata