officecli-pptx

Fail

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The setup instructions recommend installing the officecli tool via curl -fsSL https://d.officecli.ai/install.sh | bash on Unix systems and irm https://d.officecli.ai/install.ps1 | iex on Windows. This involves downloading and piping scripts directly into a shell, which is inherently risky as it executes remote code. These endpoints belong to the skill author's infrastructure (iofficeai), which qualifies them as vendor resources rather than anonymous threats.
  • [EXTERNAL_DOWNLOADS]: The skill downloads installation scripts from d.officecli.ai and provides links to binary releases on GitHub. These downloads are necessary for the skill's primary function and originate from the vendor's own repositories.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads and processes existing .pptx files using several inspection commands. This creates a risk where malicious instructions embedded in a presentation could influence the assistant's behavior.
  • Ingestion points: Commands such as officecli view outline, view text, and get read existing file content into the agent's context.
  • Boundary markers: No specific delimiters or safety instructions are provided to help the agent distinguish between slide content and its own instructions.
  • Capability inventory: The skill has powerful file modification capabilities (add, set, remove, batch) that could be misused if an injection occurs.
  • Sanitization: There is no evidence of filtering or sanitizing the text extracted from input files.
Recommendations
  • HIGH: Downloads and executes remote code from: https://d.officecli.ai/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 16, 2026, 12:41 PM
Security Audit — agent-trust-hub — officecli-pptx