AI/TLDR

PromptArmor · 2026-06-01 · major

PromptArmor: ChatGPT for Google Sheets Exfiltrates Workbooks — One Poisoned Sheet Steals Up to 12 Workbooks via Apps Script, OpenAI Pulls the Code-Gen Path After Disclosure Slipped Through Their Pipeline

PromptArmor showed a single hidden prompt in one Google Sheet could push the ChatGPT Sheets extension to write Apps Script that silently exfiltrates other workbooks and paints a phishing chatbot over the UI. OpenAI disabled Apps Script generation.

PromptArmor report header for ChatGPT for Google Sheets workbook exfiltration

One hidden instruction in a shared sheet hijacks the ChatGPT Sheets extension and walks out with workbooks across the user's account.

Key specs

Extension installs185,000+
Workbooks exfiltrated per hitup to 12
Hn front page points211
Hn comments64

What is it?

PromptArmor disclosed an indirect prompt injection in OpenAI's ChatGPT for Excel and Google Sheets extension, the official sidebar that lets users ask GPT to read and edit a sheet. They showed that a single poisoned sheet could trigger silent data exfiltration and overlay a fake chatbot, with no clicks beyond the user's original 'summarise this sheet' prompt.

How does it work?

Untrusted data in a sheet — pasted text, an imported CSV, a connector pull — hides instructions for the model. When the user asks a benign question, the extension follows the hidden directions instead and emits Apps Script that runs with the permissions the user already granted at install time. The script reads other open workbooks, posts contents to an attacker endpoint, and rewrites cells to render a phishing chatbot. PromptArmor reports up to twelve workbooks pulled per attack and notes the path runs even with auto-edits disabled.

Why does it matter?

It is the second major Sheets-AI prompt injection PromptArmor has disclosed (Ramp's Sheets AI was the first) and the first to land on the official OpenAI extension, which has more than 185,000 installs across Workspace tenants. After PromptArmor went public, OpenAI removed the model's ability to generate Apps Script and acknowledged the report had been stuck on their automated disclosure queue since May 8. Workspace admins can restrict the extension via Permissions and Roles in the meantime.

Who is it for?

Workspace admins, security teams, anyone running the ChatGPT Sheets extension

Try it

Workspace Admin > Apps > Marketplace apps > restrict 'ChatGPT for Excel and Google Sheets'

Sources · 3 outlets

Tags

  • security
  • prompt-injection
  • data-exfiltration
  • chatgpt
  • google-sheets
  • apps-script
  • indirect-prompt-injection
  • openai
  • responsible-disclosure

← All releases · Learn AI