officecli-financial-model
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The setup instructions direct the user to download and execute shell scripts from a remote domain (
d.officecli.ai) using patterns likecurl | bashandirm | iex. While these represent the vendor's official installation method, they are inherently high-risk patterns. - Evidence:
curl -fsSL https://d.officecli.ai/install.sh | bashandirm https://d.officecli.ai/install.ps1 | iexinSKILL.md. - [DYNAMIC_EXECUTION]: The skill uses
python3 -cto perform calculations on variables that are directly interpolated from shell environment variables. These variables ($STATED,$PLUGGED) contain data read from external Excel cells. If these cells contain malicious content, they could potentially execute arbitrary Python code during the audit gates. - Evidence: `python3 -c "print(abs(float('$STATED')
- float('$PLUGGED')))"
inSKILL.md`. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from Excel files (
.xlsx) and uses the results to drive control flow decisions and audit checks without explicit sanitization. - Ingestion points: Data enters the context via
officecli getandofficecli querycommands executed on the target Excel file inSKILL.md. - Boundary markers: No delimiters or instructions to ignore embedded commands are present when processing cell values.
- Capability inventory: The skill uses
officecli(file read/write),bash(shell execution), andpython3(dynamic code evaluation). - Sanitization: There is no evidence of validation or escaping for cell values before they are used in shell variables or Python commands.
- [COMMAND_EXECUTION]: The skill relies heavily on shell piping and command substitution to perform data validation and audit gates, which increases the attack surface for injection if any input sources are compromised.
- Evidence: Extensive use of backticks and
$()for command substitution throughout theSKILL.mdbuild gates.
Recommendations
- HIGH: Downloads and executes remote code from: https://d.officecli.ai/install.sh - DO NOT USE without thorough review
Audit Metadata