csv-formula-injection

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is coherent with its stated purpose, but that purpose is to teach offensive spreadsheet-exploitation techniques. It does not show malware-like installation, credential harvesting, or hidden exfiltration by the skill itself, yet it materially enables command-execution and outbound-request abuse against target spreadsheet workflows. Final classification: SUSPICIOUS / high-risk offensive security skill, not confirmed malware.

Confidence: 92%Severity: 76%
Audit Metadata
Analyzed At
Apr 9, 2026, 04:29 AM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fcsv-formula-injection%2F@9ecff85d2115f353f46d2c3269ef4b6f55dff089