Please do not publish sensitive vulnerability details in a public issue. Report them through GitHub private vulnerability reporting.
Include the affected version, a minimal reproduction, potential impact, and any suggested mitigation.
GridPluck has no backend, account system, analytics, or network API. It runs only after the user clicks the extension icon and reads only the currently loaded document structure. CSV and TSV exports prefix common spreadsheet-formula patterns to reduce formula-injection risk. This is a safeguard, not a guarantee across spreadsheet applications; inspect exports from untrusted pages before use.