officecli-financial-model

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The setup instructions direct the user to download and execute shell scripts from a remote domain (d.officecli.ai) using patterns like curl | bash and irm | iex. While these represent the vendor's official installation method, they are inherently high-risk patterns.
  • Evidence: curl -fsSL https://d.officecli.ai/install.sh | bash and irm https://d.officecli.ai/install.ps1 | iex in SKILL.md.
  • [DYNAMIC_EXECUTION]: The skill uses python3 -c to perform calculations on variables that are directly interpolated from shell environment variables. These variables ($STATED, $PLUGGED) contain data read from external Excel cells. If these cells contain malicious content, they could potentially execute arbitrary Python code during the audit gates.
  • Evidence: `python3 -c "print(abs(float('$STATED')
  • float('$PLUGGED')))"inSKILL.md`.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from Excel files (.xlsx) and uses the results to drive control flow decisions and audit checks without explicit sanitization.
  • Ingestion points: Data enters the context via officecli get and officecli query commands executed on the target Excel file in SKILL.md.
  • Boundary markers: No delimiters or instructions to ignore embedded commands are present when processing cell values.
  • Capability inventory: The skill uses officecli (file read/write), bash (shell execution), and python3 (dynamic code evaluation).
  • Sanitization: There is no evidence of validation or escaping for cell values before they are used in shell variables or Python commands.
  • [COMMAND_EXECUTION]: The skill relies heavily on shell piping and command substitution to perform data validation and audit gates, which increases the attack surface for injection if any input sources are compromised.
  • Evidence: Extensive use of backticks and $() for command substitution throughout the SKILL.md build gates.
Recommendations
  • HIGH: Downloads and executes remote code from: https://d.officecli.ai/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 09:34 AM
Security Audit — agent-trust-hub — officecli-financial-model