officecli
Fail
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides instructions to download and execute scripts directly from an external domain using shell pipes, which is a high-risk pattern for executing unverified code.
- Evidence:
curl -fsSL https://d.officecli.ai/install.sh | bashinSKILL.md. - Evidence:
irm https://d.officecli.ai/install.ps1 | iexinSKILL.md. - [EXTERNAL_DOWNLOADS]: The skill attempts to download binaries and scripts from
officecli.ai, a domain not recognized as a trusted organization or well-known service. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (Office documents) and has broad execution capabilities, creating a significant attack surface.
- Ingestion points: The agent reads content from
.docx,.xlsx, and.pptxfiles using commands likeview,get,query, andraw(all inSKILL.md). - Boundary markers: The instructions lack delimiters or warnings to ignore embedded instructions within the processed documents.
- Capability inventory: The skill uses a CLI tool to modify the filesystem, execute shell commands, and potentially interact with the network during installation.
- Sanitization: There is no mention of sanitizing or validating the contents of the Office documents before processing them.
- [COMMAND_EXECUTION]: The core functionality of the skill involves executing the
officeclibinary and other shell commands to manipulate files and document structures.
Recommendations
- HIGH: Downloads and executes remote code from: https://d.officecli.ai/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata