officecli-data-dashboard

Fail

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides setup instructions that involve downloading a shell script from the vendor's infrastructure and piping it directly to an interpreter (bash or PowerShell).
  • Evidence: curl -fsSL https://d.officecli.ai/install.sh | bash in SKILL.md.
  • Evidence: irm https://d.officecli.ai/install.ps1 | iex in SKILL.md.
  • [EXTERNAL_DOWNLOADS]: The skill fetches configuration and installation assets from external domains associated with the project and the developer's GitHub repository.
  • Evidence: Fetches installation scripts from d.officecli.ai.
  • Evidence: Directs users to download binaries from the iOfficeAI/OfficeCLI repository on GitHub.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data files which presents an attack surface for indirect prompt injection.
  • Ingestion points: The skill is designed to import data from CSV files (e.g., sales.csv referenced in SKILL.md) and tabular inputs.
  • Boundary markers: No explicit boundary markers or safety instructions are defined to delimit external data from agent instructions during processing.
  • Capability inventory: The skill uses the officecli tool to perform file creation, modification, and structural validation of Excel workbooks. It also employs shell utilities like jq, bc, and awk for data manipulation.
  • Sanitization: There is no mention of sanitizing or validating the content of the imported CSV files to prevent the execution of embedded commands or instructions.
Recommendations
  • HIGH: Downloads and executes remote code from: https://d.officecli.ai/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 3, 2026, 09:23 AM
Security Audit — agent-trust-hub — officecli-data-dashboard