officecli-academic-paper
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill includes instructions to download and execute setup scripts using unsafe shell patterns. Evidence: 'curl -fsSL https://d.officecli.ai/install.sh | bash' for macOS/Linux and 'irm https://d.officecli.ai/install.ps1 | iex' for Windows.
- [COMMAND_EXECUTION]: The skill relies on executing a local CLI tool ('officecli') to manage Word document creation and validation, which involves frequent shell command execution.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided text to build academic documents, creating an injection surface. Ingestion points: User-supplied research paper text, citations, and abstracts. Boundary markers: None specified in command examples. Capability inventory: File system writes and CLI tool execution. Sanitization: No explicit instructions for escaping or validating user-provided content before inclusion in shell commands.
Recommendations
- HIGH: Downloads and executes remote code from: https://d.officecli.ai/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata