officecli-academic-paper

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill includes instructions to download and execute setup scripts using unsafe shell patterns. Evidence: 'curl -fsSL https://d.officecli.ai/install.sh | bash' for macOS/Linux and 'irm https://d.officecli.ai/install.ps1 | iex' for Windows.
  • [COMMAND_EXECUTION]: The skill relies on executing a local CLI tool ('officecli') to manage Word document creation and validation, which involves frequent shell command execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided text to build academic documents, creating an injection surface. Ingestion points: User-supplied research paper text, citations, and abstracts. Boundary markers: None specified in command examples. Capability inventory: File system writes and CLI tool execution. Sanitization: No explicit instructions for escaping or validating user-provided content before inclusion in shell commands.
Recommendations
  • HIGH: Downloads and executes remote code from: https://d.officecli.ai/install.sh - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 05:18 PM
Security Audit — agent-trust-hub — officecli-academic-paper