When a model prepares spreadsheet data, an untrusted label remains data even if it resembles a formula or an instruction. CSV stores fields, not cell types; a spreadsheet application may interpret a leading formula character as an executable expression when the file is opened. Check each exported field after serialization and again in the target spreadsheet application, especially values starting with equals, plus, minus, at-sign, tabs, or line breaks. Quoting a CSV field addresses separators and quotes but does not by itself force text interpretation in every spreadsheet client. If the export format supports explicit text cell types, use them; otherwise choose and verify a client-specific neutralization policy. Preserve the original untrusted value separately for audit rather than silently rewriting it.
Spreadsheet exports: keep untrusted labels as text
Operational case
One Stock row has the supplier label '=1+1' as literal text. The assistant treats it as a harmless SKU note and produces a CSV export. A reviewer opens it in a spreadsheet program and sees a computed value instead of the label. The team switches to a workbook export with the supplier label written as a text-typed cell, then reopens that file in the target program to confirm the visible value is the literal label. The inventory formulas remain in approved F cells; the supplier column never becomes a formula channel. A CSV delivery, if required, gets a separately tested escaping policy for that application and a save-and-reopen check.
Untrusted supplier label: =1+1 (literal text).
Allowed formula cells: Stock!F2:F48 only.
Preferred export: explicit text cell type for supplier labels.
CSV fallback: client-tested neutralization; open, save, reopen, inspect.
Retain raw source label in the audit record.Performance and operating cost
Scanning N exported fields costs O(N) time and O(1) extra space per field in a streaming exporter, excluding the output buffer. A manual open-and-reopen test costs more but checks the client behavior that a string scan cannot prove. A prompt saying 'do not execute formulas' cannot control how a spreadsheet program imports CSV. The correct boundary is at serialization and application import, with raw and exported representations kept distinct. Review also covers embedded delimiters and line breaks so one attacker-controlled value cannot shift content into another cell.
Common Mistakes
- Do not assume CSV quotes make formula-looking values safe as text.
- Do not treat a prompt instruction as a substitute for typed export or client testing.
- Do not alter raw audit data without recording the exported transformation.
Connected lessons
- Prompt engineering applications
- Prompt Engineering
- Python CSV export: spreadsheet cells are an execution boundary
- Python CSV headers: reject duplicate names before row mapping
- Prompt envelopes: separate task, evidence, input, and output contract
- Workbook prompts: name sheets, ranges, types, and provenance
- Formula prompts: test references, types, and fill behavior
- Workbook edits: review a cell diff before applying changes
- Spreadsheet release checks: recalculate, reconcile, then inspect
- Project: review a depot replenishment workbook
- Spreadsheet prompt and workbook release decisions
