Back to skill

Security audit

officecli-pptx

Security checks for vulnerabilities and agentic risk

Overview

This PPTX skill is mostly coherent, but it tells agents to install its required tool by directly running an unverified remote script.

Install only if you are comfortable with the OfficeCLI installer source. Prefer downloading a pinned release from the project release page and verifying its integrity instead of running the pipe-to-shell or PowerShell iex commands. Be aware the skill may activate on broad presentation-related words, so confirm the agent is working only on the intended PPTX files before allowing edits or setup.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:10
Finding

Unverified Remote Installer Scripts Are Executed Directly

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10–15
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Complete Code Snippet:

markdown
If `officecli` is missing:

- **macOS / Linux**: `curl -fsSL https://d.officecli.ai/install.sh | bash`
- **Windows (PowerShell)**: `irm https://d.officecli.ai/install.ps1 | iex`

Verify with `officecli --version` (open a new terminal if PATH hasn't picked up). If install fails, download a binary from https://github.com/iOfficeAI/OfficeCLI/releases.

Technical Analysis

The installation instructions retrieve mutable scripts from an external domain and immediately execute them through Bash or PowerShell. The downloaded content is not pinned to a version, saved for inspection, checked against a cryptographic digest, or verified using a publisher signature.

Consequently, the code that executes can differ from the content available when this Skill was reviewed. The external installer scripts are not included in the project, so their behavior cannot be established through this static audit. HTTPS protects transport integrity under normal conditions but does not mitigate compromise of the hosting infrastructure, publication account, DNS/TLS trust chain, or installer release process.

Installation is relevant to the declared PPTX functionality, but direct execution of an unverified network response is not the minimum necessary approach. The document itself identifies downloadable GitHub release artifacts as an alternative.

Attack Path

  1. An Agent loads the Skill and determines that officecli is unavailable.
  2. The Agent follows the prescribed setup command.
  3. An attacker who controls or compromises the installer domain, hosting account, deployment pipeline, DNS resolution, or trusted TLS path modifies the returned script.
  4. curl pipes the response directly to Bash, or irm passes it directly to iex, without an inspe ...[truncated 1169 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both direct execution patterns:
    • curl ... | bash
    • irm ... | iex
  2. Pin installation to an exact, immutable OfficeCLI release rather than a mutable installer endpoint.
  3. Download the release artifact to disk without executing it.
  4. Publish and verify a SHA-256 or stronger checksum through an independently protected release channel.
  5. Prefer cryptographic publisher signatures and validate the signing identity before installation.
  6. Present the artifact source, version, checksum, and intended destination to the user and require explicit approval before installing.
  7. Install only with the invoking user's permissions unless a specific operation demonstrably requires elevation. Do not request sudo or administrator access by default.
  8. Prefer a trusted package manager or a vendored, auditable installer whose version and integrity are locked.
  9. Document the files, PATH changes, network access, and other system modifications performed by installation.
  10. If a script installer remains necessary, separate retrieval from execution so it can be reviewed first, and fail closed when signature or checksum validation does not succeed.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest description contains very broad activation triggers such as any mention of 'deck', 'slides', 'presentation', 'pitch', or any .pptx filename. This can cause the skill to activate in contexts beyond the user's intent, increasing the chance that risky instructions in the skill—such as software installation or file-manipulation workflows—are invoked unnecessarily.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The skill instructs users to install software by piping a remotely fetched script directly into a shell (curl ... | bash and PowerShell irm ... | iex). This bypasses integrity review and turns compromise of the remote host, DNS, TLS trust chain, or distribution endpoint into immediate arbitrary code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
If `officecli` is missing:

- **macOS / Linux**: `curl -fsSL https://d.officecli.ai/install.sh | bash`
- **Windows (PowerShell)**: `irm https://d.officecli.ai/install.ps1 | iex`

Verify with `officecli --version` (open a new terminal if PATH hasn't picked up). If install fails, download a binary from https://github.com/iOfficeAI/OfficeCLI/releases.

Static analysis

No suspicious patterns detected.