Back to skill

Security audit

officecli-docx

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent DOCX editing guide, but its setup asks users to run an unaudited remote installer directly in a shell.

Review before installing. The DOCX workflow itself is understandable, but avoid the pipe-to-shell setup unless you trust the OfficeCLI publisher and have an integrity-verified install path. Prefer a pinned release with checksums or signatures, and invoke this skill only for actual .docx or Microsoft Word tasks.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:10
Finding

Unverified Remote Installer Scripts Are Executed Directly

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10–15
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

markdown
## Setup

If `officecli` is missing:

- **macOS / Linux**: `curl -fsSL https://d.officecli.ai/install.sh | bash`
- **Windows (PowerShell)**: `irm https://d.officecli.ai/install.ps1 | iex`

Verify with `officecli --version` (open a new terminal if PATH hasn't picked up). If install fails, download a binary from https://github.com/iOfficeAI/OfficeCLI/releases.

Technical Analysis

Both installation commands retrieve mutable scripts from d.officecli.ai and immediately execute the responses with Bash or PowerShell. They provide no opportunity for inspection and perform no version pinning, cryptographic signature validation, or checksum verification.

The actual installers are not included in the audited project. Consequently, their behavior, installed files, requested permissions, dependencies, and potential persistence mechanisms cannot be statically assessed. The external server can also change the delivered payload after this Skill has been reviewed.

Installing a DOCX utility may be necessary for the declared functionality, but granting an unverified network response immediate code-execution rights is not the minimum safe mechanism. The GitHub release fallback does not establish the integrity of scripts delivered through the separate custom domain.

Attack Path

  1. The Skill is activated for a document-related task.
  2. The required officecli executable is not installed.
  3. An agent or user follows the setup instructions.
  4. The command retrieves the current installer response from d.officecli.ai.
  5. Bash or PowerShell executes that response immediately, without integrity verification.
  6. If the hosting service, publication pipeline, DNS/TLS delivery chain, or installer content is compromised, attacker-controlled commands execute with the privileges of the i ...[truncated 614 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both direct download-to-interpreter pipelines.
  2. Pin installation to a specific, immutable OfficeCLI release and version.
  3. Download the artifact separately rather than immediately executing a network response.
  4. Publish and verify a trusted SHA-256 checksum or cryptographic signature before installation.
  5. Prefer a reputable package manager with locked versions and integrity metadata where available.
  6. Require explicit user approval before installing or executing third-party software.
  7. Document the files, PATH changes, network access, and permissions required by the installer.
  8. Avoid administrative execution unless a documented installation step strictly requires it.
  9. If scripts remain necessary, host versioned immutable copies, verify their signatures, and instruct users to inspect them before execution.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger text is extremely broad, matching generic terms like 'document', 'report', 'letter', and 'memo', which can cause this skill to activate in many contexts unrelated to DOCX handling. Over-broad invocation increases attack surface by causing an agent to enter a tool-using workflow unnecessarily, including installation and shell-command guidance, when a simpler or safer path would suffice.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The skill instructs users to execute remote scripts directly from the network via shell and PowerShell piping (curl ... | bash, irm ... | iex). This is dangerous because it grants immediate code execution to whatever content is served at that URL or intercepted in transit, creating a straightforward supply-chain and remote code execution risk.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
If `officecli` is missing:

- **macOS / Linux**: `curl -fsSL https://d.officecli.ai/install.sh | bash`
- **Windows (PowerShell)**: `irm https://d.officecli.ai/install.ps1 | iex`

Verify with `officecli --version` (open a new terminal if PATH hasn't picked up). If install fails, download a binary from https://github.com/iOfficeAI/OfficeCLI/releases.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The instructions require all new content to use curly quotes and specific dash conventions as mandatory output rules. This imposes a particular language/typography convention globally, without offering the user a locale or style choice or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.