Security, Governance and Platform · Principal
The agent wrote a CSV report. Why did opening it run a formula from a customer name?
The question
Interview question
An agent exports support cases to CSV for a finance reviewer. A customer-controlled name starts with `=HYPERLINK(...)`. The agent quotes the field correctly according to CSV syntax. The reviewer opens the file in a spreadsheet app, where the cell is treated as a formula. What boundary did the export cross?
Take a few minutes to form your approach. Then open a worked answer and compare the decisions.
Reveal a worked answer
CSV quoting protects the record format. It does not guarantee that the spreadsheet will interpret a cell as inert text. The untrusted name moved from data in a support system into a program-like language understood by the spreadsheet. OWASP's CSV injection guidance and Web Security Testing Guide call out formulas in exported user-controlled cells and the danger of relying on simple quoting or escaping that may not survive save and reopen. The AI angle is that a model may make the report, but output encoding remains an application responsibility. “The agent generated it” is not a sanitation policy.
I would determine whether the app supplied raw data and a controlled exporter, or allowed the model to assemble arbitrary CSV bytes. The latter is harder to secure. Use a typed export tool: columns, row values and declared data types go to code that owns the CSV or spreadsheet serialization. Treat every customer-entered field and tool-derived string as untrusted, including fields that appear later in the row. An attacker can put a delimiter or newline inside a value so that a dangerous character becomes the first character of a new cell if the writer is wrong. Formula-like prefixes include more than = in common spreadsheet programs, so test the actual readers and locale settings. Keep the original value for the system of record, and transform only the exported representation.
When the workflow requires spreadsheet editing, a real spreadsheet file with cells explicitly written as strings can make the intended type clearer. Still verify the target applications and round trip behavior. For CSV, use a defense appropriate to the consumers and document its limits. OWASP notes that some spreadsheet programs may remove an escape on save and reopen. If the report contains sensitive information, also check any formula functions that could refer to external resources, but do not claim every spreadsheet or setting automatically makes a network request. The exploit depends on the consumer.
I would test names beginning with =, +, -, @, whitespace or control characters, embedded commas, quotes and line breaks, then open, save and reopen the result in supported spreadsheet apps. Check every field, not just the first column. The model can choose which cases to include and explain them. The serializer must prevent untrusted data from becoming executable spreadsheet content. The assistant's answer loads an external URL covers an assistant answer loading an external URL. This is a different output interpreter and a different trust boundary.
Continue reading
Related questions
Read beyond the question
Explore more security, governance and platform
Follow another question in this area, or search the complete Question Library.
Browse this area →Browse Question Library →