Privacy-first browser CSV cleaner with destination-aware formula-prefix handling.
-
Updated
Jul 19, 2026 - TypeScript
Privacy-first browser CSV cleaner with destination-aware formula-prefix handling.
A zero-config, language-agnostic gate that statically flags CSV/formula injection - code writing user-controlled data to CSV/spreadsheet output without neutralizing the formula-trigger characters (= + - @ tab CR) that let a cell execute in Excel/Sheets. Single Go binary. Grounded in OWASP CSV Injection / CWE-1236.
Privacy-first GitHub Action for auditing CSV formula-injection risk
Secure output sanitization and input inspection for JSON/JSONL, CSV, and TSV — guards against formula injection, bidi-override, control-character, and encoding attacks.
Add a description, image, and links to the formula-injection topic page so that developers can more easily learn about it.
To associate your repository with the formula-injection topic, visit your repo's landing page and select "manage topics."