Practical digital skills

Check CSV formulas before sharing

Separate text from formulas during import, preserve the original and inspect the delivered file rather than its preview alone.

Step-by-step guideUpdated
Follow the method ↓
Editorial illustration of a spreadsheet review on a computer
Generic illustration of a data check.

The answer in 30 seconds

A CSV contains text, but spreadsheet software can interpret some cells as formulas. Exports containing third-party input deserve particular attention. Encoding and delimiter checks alone do not cover this interpretation.

Keep the original, explicitly import affected fields as text and inspect cell beginnings in each column. OWASP explains that no CSV neutralisation works universally for all spreadsheet applications and downstream uses.

Examples to adapt

A form export

A response should remain text. Have untrusted fields reviewed before distributing the export.

Negative numbers

Preserve their numerical meaning in designated columns; treat free-text comments separately.

Follow the method

  1. 1
    Identify field origins

    Locate comments, names and descriptions originating in external input. Preserve the raw CSV and work on a copy.

  2. 2
    Prepare import

    Calc documentation distinguishes Text column type and Evaluate formulas. Choose suitable options before loading. Excel’s Text/CSV import supports column control.

  3. 3
    Inspect content

    A cell beginning with = can be interpreted as a formula. OWASP identifies other initiating characters depending on the application. Do not blindly remove legitimate negative values.

  4. 4
    Check the final copy

    Compare row counts, identifiers and content with the original. Check the delivery file’s behaviour in the intended environment; do not assume escaping survives saving and reopening.

A checklist to keep

Use these checks to record your observations. They are a reading aid, not an automatic assessment.

Check CSV formulas before sharing: checklist
CheckWhat to examineAction
OriginThird-party input fieldsIdentify
TypeExpected text or numberDefine per column
ImportFormula and text settingsCheck
FidelityRows, identifiers and valuesCompare against original
DeliveryIntended software and useDocument limits

Download the CSV checklist

Free, no sign-up. UTF-8 text with semicolon-separated columns.

What to check

Quoting a cell does not guarantee text interpretation in every application.

A spreadsheet-oriented protection can alter data read by a program.

Import settings and receiving software are part of the context to retain.

Common questions

Should I remove every minus sign?

No. That would alter valid values. Define each column’s intended type and handle untrusted fields separately.

Must I test a dangerous formula?

No. Document import settings and use a harmless example in an authorised test environment.

Sources and documentation

Documentation consulted on . Examples are illustrative; interfaces and results may change.

Reference record for this resource

Identify the publisher, official destination and practical checks before using the service.

Read the OWASP record →

Continue exploring

All English guides →