Skip to tool

LOCAL XLSX EVIDENCE WORKBENCH

Spreadsheet Formula & Hidden-Link Forensics Lab

Inventory formulas, hidden structures and outbound workbook relationships without uploading the file, then export review-ready evidence.

Public quality review · 2026-07-27

Reviewed public workflow · ads off
Browser-local 5 artifacts + Receipt v1 Formulas never run

Loading Spreadsheet Forensics Lab...

PUBLIC METHODOLOGY NOTE

What is inspected—and what is deliberately not inferred

The lab opens the XLSX ZIP directory, resolves workbook and worksheet relationships, reads formulas as inert text, and records hidden states, defined names, calculation flags and external targets. It does not execute Excel, formulas, macros or network calls.

Review-signal model

Signals include external-workbook references, network-capable or dynamic-reference formula families, hidden and veryHidden sheets, hidden defined names, external relationships, manual calculation and iteration flags. Context determines whether a signal is legitimate.

Formula diff contract

Comparison is keyed by normalized sheet name and cell address. Added, removed and text-changed formulas are reported; formulas are not recalculated and semantic equivalence is not claimed.

Sources and implementation boundary

Privacy: workbook bytes, formulas and hashes stay in this tab. Normal requests for FastTool’s static assets may still be visible to the network.

Important: This is a structural and formula-review aid, not a malware detector and not proof that a workbook is safe.

WORKBOOK HANDOFF PLAYBOOK

Inspect the structures a normal spreadsheet review can miss

A workbook can look ordinary while still carrying hidden sheets, concealed names, external-workbook targets, manual-calculation settings, volatile formulas, or formula changes outside the visible review area. This workbench inventories those structures without opening Excel and without executing workbook logic. The output is a review queue: it tells a human exactly which sheet, cell, relationship, or defined name needs context before the file is trusted or shared.

Before sharing

Run the workbook alone, inspect every BLOCK or INDETERMINATE item, and confirm whether each hidden object and external target has an accountable business purpose. If the workbook came from outside your organization, review it on an isolated device under your normal file-handling policy.

Before approving a change

Add the prior workbook as the comparison file. Treat added, removed, or text-changed formulas as a bounded diff, not proof of semantic equivalence. Recalculate in the approved spreadsheet application only after the structural review is complete.

When the result blocks

Do not delete every flagged item automatically. A hidden calculation sheet or external price feed may be intentional. Record the owner, purpose, expected target, and remediation decision; then rerun the exact bytes and preserve the new receipt as the review record.

When evidence is incomplete

Encrypted files, legacy XLS, macros, Power Query, embedded binaries, runtime network behavior, and formula results are outside this parser. INDETERMINATE is the correct outcome when those surfaces matter. Escalate to an approved sandbox or spreadsheet-security workflow instead of treating absence of evidence as safety.

How to read the evidence pack

The JSON preserves the complete bounded analysis; the findings CSV is a formula-injection-safe review queue; the dependency CSV exposes conservative cell-to-cell edges; the Markdown file is a human handoff; and the SVG is a visual map of formula and hidden-link structure. Receipt v1 binds the exact workbook input, generated artifact bytes, engine version, assumptions, limits, and receipt-core hash. A PASS means the selected policy found no blocking signal in supported OOXML structures—it is not a malware certificate or a guarantee that every calculation is correct.

Publisher and QA: FastTool product engineering maintains this method. The current EN/TR Chromium and WebKit matrix, hostile ZIP/input checks, stale-state tests, formula-injection-safe CSV check, artifact byte/hash parity, and independent red-team review are recorded in the public quality manifest. Corrections can be submitted through the accountable correction channel.