T09 · Insecure Skill Coding Practices
- Location
scripts/csv_builder.py:53- Finding
CSV Formula Injection in Spreadsheet-Bound Lead Exports
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent LinkedIn lead workflow with local CSV utilities, but users should handle exported prospect data and spreadsheet imports carefully.
Install only if you are comfortable using it for review-first lead research. Keep prospect exports limited to necessary business data, store them securely, delete them when no longer needed, and sanitize CSV cells before opening externally sourced lead data in Google Sheets or Excel.
scripts/csv_builder.py:53CSV Formula Injection in Spreadsheet-Bound Lead Exports
The skill references local scripts that read and write files (scripts/csv_builder.py, scripts/sheets_prep.py, scripts/dashboard_stats.py) but does not declare any explicit tool scope or permissions. In an agent environment, this can lead to overbroad filesystem access assumptions, making it easier for the skill to read unintended files or write sensitive prospect data to unexpected locations without clear operator review.
The skill is designed to collect, score, message, and export personal prospect data, including names, LinkedIn URLs, titles, locations, and personalization signals, yet it does not warn users about privacy, lawful basis, retention, or safe handling of exported data. This increases the risk of inappropriate collection, oversharing, or insecure storage of personal data during lead-generation workflows.
No suspicious patterns detected.