officecli-xlsx
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The setup section provides commands to download and execute an installation script directly from the vendor's domain (
https://d.officecli.ai/install.shfor macOS/Linux andhttps://d.officecli.ai/install.ps1for Windows). This is a standard installation pattern for the requiredofficeclitool. - [EXTERNAL_DOWNLOADS]: The skill references binary downloads from the vendor's GitHub repository (
https://github.com/iOfficeAI/OfficeCLI/releases) as a fallback if the automated installation script fails. - [COMMAND_EXECUTION]: The skill operates by executing various
officeclicommands through the shell to create, read, and modify spreadsheet files. It includes specific guidance on shell quoting and the use of heredocs to prevent character mangling by the shell. - [DYNAMIC_EXECUTION]: The skill provides a Python script template (
gen_batch.py) that generates JSON batch commands based on CSV input. These generated commands are then piped intoofficecli batchfor execution. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external data from .xlsx and .csv files, which creates a potential surface for indirect prompt injection if those files contain malicious instructions meant to influence the agent's behavior.
- Ingestion points: Data enters the context via
officecli view(outline, text, annotated, issues),officecli import, and the processing of CSV files via the provided Python recipe. - Boundary markers: The instructions do not explicitly mandate the use of delimiters or specific "ignore" instructions for the content of the spreadsheets being processed.
- Capability inventory: The skill utilizes filesystem write capabilities and shell command execution via the
officeclibinary. - Sanitization: The skill provides detailed instructions on quoting shell metacharacters and property values to ensure correct execution and data handling.
Audit Metadata