officecli-pptx
Fail
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The setup instructions recommend installing the officecli tool via
curl -fsSL https://d.officecli.ai/install.sh | bashon Unix systems andirm https://d.officecli.ai/install.ps1 | iexon Windows. This involves downloading and piping scripts directly into a shell, which is inherently risky as it executes remote code. These endpoints belong to the skill author's infrastructure (iofficeai), which qualifies them as vendor resources rather than anonymous threats. - [EXTERNAL_DOWNLOADS]: The skill downloads installation scripts from d.officecli.ai and provides links to binary releases on GitHub. These downloads are necessary for the skill's primary function and originate from the vendor's own repositories.
- [INDIRECT_PROMPT_INJECTION]: The skill reads and processes existing .pptx files using several inspection commands. This creates a risk where malicious instructions embedded in a presentation could influence the assistant's behavior.
- Ingestion points: Commands such as
officecli view outline,view text, andgetread existing file content into the agent's context. - Boundary markers: No specific delimiters or safety instructions are provided to help the agent distinguish between slide content and its own instructions.
- Capability inventory: The skill has powerful file modification capabilities (add, set, remove, batch) that could be misused if an injection occurs.
- Sanitization: There is no evidence of filtering or sanitizing the text extracted from input files.
Recommendations
- HIGH: Downloads and executes remote code from: https://d.officecli.ai/install.sh - DO NOT USE without thorough review
Audit Metadata