officecli-docx
Fail
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download the
officeclitool. - URLs:
https://d.officecli.ai/install.sh,https://d.officecli.ai/install.ps1, andhttps://github.com/iOfficeAI/OfficeCLI/releases. - These resources are managed by the skill's author,
iofficeai, and represent intended vendor infrastructure. - [REMOTE_CODE_EXECUTION]: Setup instructions involve executing remote scripts via shell piping.
- Pattern:
curl -fsSL https://d.officecli.ai/install.sh | bash. - Pattern:
irm https://d.officecli.ai/install.ps1 | iex. - These patterns are used for the initial installation of the vendor's command-line interface tool.
- [COMMAND_EXECUTION]: The skill operates by executing the
officeclibinary through various shell commands. - Commands used:
create,open,add,set,view,query,validate, andsave. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external
.docxfiles, creating a potential attack surface. - Ingestion points: Document content is read using
officecli view "$FILE" textand document metadata/structure is inspected viaofficecli view "$FILE" outlineinSKILL.md. - Boundary markers: The skill includes instructions to quote shell arguments and single-quote values containing shell metacharacters (e.g.,
$) to prevent content from being misinterpreted as commands. - Capability inventory: The skill utilizes the
officeclitool which has capabilities for file system writes, document modification, and raw OOXML injection (raw-set). - Sanitization: The skill relies on recommended shell-quoting discipline and a mandatory QA cycle (including schema validation and visual checks) rather than automated sanitization routines to ensure document integrity.
Recommendations
- HIGH: Downloads and executes remote code from: https://d.officecli.ai/install.sh - DO NOT USE without thorough review
Audit Metadata