officecli-pitch-deck
Fail
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides setup instructions for the required
officeclitool that involve downloading scripts and piping them directly to the shell. Specifically, it usescurl -fsSL https://d.officecli.ai/install.sh | bashfor macOS/Linux andirm https://d.officecli.ai/install.ps1 | iexfor Windows. While these resources are hosted on domains associated with the skill's author (iofficeai), the pattern of piping remote content to a shell is a significant capability. - [COMMAND_EXECUTION]: The skill instructs the agent to execute the
officeclibinary via the shell to create and modify PowerPoint presentations. It relies onofficecli batchfor complex operations and direct CLI calls for slide management. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection.
- Ingestion points: The agent ingests untrusted user data describing startup stages, revenue metrics, team credentials, and market data (found in
SKILL.md). - Boundary markers: No explicit delimiters are used to separate user-provided data from the command structure in the provided templates.
- Capability inventory: The skill uses subprocess calls to execute shell commands (
officecli). - Sanitization: The skill includes a 'Shell & Execution Discipline' section that instructs the agent to use single quotes (
--prop text='...') for strings containing$to prevent shell expansion. However, there is no comprehensive sanitization or validation for other shell metacharacters in the user-controlled data.
Recommendations
- HIGH: Downloads and executes remote code from: https://d.officecli.ai/install.sh - DO NOT USE without thorough review
Audit Metadata