officecli-word-form
Fail
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides commands to download and execute remote shell and PowerShell scripts directly from the internet to install the 'officecli' tool. These commands pipe the remote content into a shell interpreter (bash or iex), which is a significant execution vector. Evidence:
curl -fsSL https://d.officecli.ai/install.sh | bashandirm https://d.officecli.ai/install.ps1 | iex. The resources originate from the vendor's infrastructure (officecli.ai). - [EXTERNAL_DOWNLOADS]: The skill references external download locations for its required binaries and installation scripts, including 'd.officecli.ai' and GitHub releases under the 'iOfficeAI' organization. These are vendor-owned resources necessary for the skill's primary functionality.
- [INDIRECT_PROMPT_INJECTION]: The skill extracts structure and text from Word documents (.docx) to drive its logic and command generation. This creates a surface for indirect prompt injection if the agent processes a document containing malicious instructions designed to influence the agent's behavior during the 'view' or 'query' steps.
- Ingestion points: Data ingested from documents via
officecli view forms,officecli query, andofficecli rawcommands. - Boundary markers: The skill does not provide specific instructions to the agent to disregard content found within the document fields.
- Capability inventory: The agent has access to
bash,python3,jq, and theofficeclitool to modify the file system and potentially interact with the network. - Sanitization: No explicit sanitization of extracted document content is mentioned before it is processed by subsequent tools.
- [DYNAMIC_EXECUTION]: The skill includes a 'Block-level lock' recipe that dynamically generates and executes a Python script to manipulate the XML structure of a document. Evidence: The use of
python3 -cto extract and wrap paragraph XML. - [COMMAND_EXECUTION]: The skill relies on numerous shell commands to perform document manipulation, including adding elements, setting properties, and validating the final document schema. It also makes use of utility tools like
jqandgrepto parse command output.
Recommendations
- HIGH: Downloads and executes remote code from: https://d.officecli.ai/install.sh - DO NOT USE without thorough review
Audit Metadata