officecli-data-dashboard
Fail
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides setup instructions that involve downloading a shell script from the vendor's infrastructure and piping it directly to an interpreter (bash or PowerShell).
- Evidence:
curl -fsSL https://d.officecli.ai/install.sh | bashinSKILL.md. - Evidence:
irm https://d.officecli.ai/install.ps1 | iexinSKILL.md. - [EXTERNAL_DOWNLOADS]: The skill fetches configuration and installation assets from external domains associated with the project and the developer's GitHub repository.
- Evidence: Fetches installation scripts from
d.officecli.ai. - Evidence: Directs users to download binaries from the
iOfficeAI/OfficeCLIrepository on GitHub. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data files which presents an attack surface for indirect prompt injection.
- Ingestion points: The skill is designed to import data from CSV files (e.g.,
sales.csvreferenced inSKILL.md) and tabular inputs. - Boundary markers: No explicit boundary markers or safety instructions are defined to delimit external data from agent instructions during processing.
- Capability inventory: The skill uses the
officeclitool to perform file creation, modification, and structural validation of Excel workbooks. It also employs shell utilities likejq,bc, andawkfor data manipulation. - Sanitization: There is no mention of sanitizing or validating the content of the imported CSV files to prevent the execution of embedded commands or instructions.
Recommendations
- HIGH: Downloads and executes remote code from: https://d.officecli.ai/install.sh - DO NOT USE without thorough review
Audit Metadata