OpenAI Strips Apps Script from Sheets After Leak

SkimNews Take
The vulnerability of AI-driven productivity tools to data exfiltration through indirect prompt injection reveals a new class of supply chain risk, where the "software" is the model's output rather than its code.
Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- ChatGPT for Google Sheets has amassed over 185,000 downloads within its first month of launch, letting users chat with AI directly from a spreadsheet sidebar.
- ChatGPT for Google Sheets is vulnerable to indirect prompt injection that can exfiltrate workbooks across the victim’s account, display phishing pop‑ups, overwrite the sidebar, and edit spreadsheets without user approval.
- OpenAI responded by removing the model’s ability to generate Apps Script code, cutting the script‑execution pathway used in the attack.
- OpenAI is re‑evaluating its sandboxing approach and reviewing similar functionality across other surfaces to ensure consistent defenses against prompt‑injection attacks.
Why it matters: Enterprises lose control over sensitive spreadsheet data, while OpenAI faces reputational risk and must invest in stronger safeguards, potentially slowing its rollout of AI‑enhanced productivity tools.




