AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL unreviewed Apache-2.0 Self-run

Officecli Word Form

skill-zhu1090093659-deepseek-pp-officecli-word-form · by zhu1090093659

Use this skill to create fillable Word forms (.docx) with real Content Controls (SDT) + legacy FormField checkboxes + MERGEFIELD mail-merge placeholders + document protection. Trigger on: 'fillable form', 'form fields', 'content controls', 'SDT', 'word form', 'fill in', 'only editable fields', 'protect document', 'onboarding form', 'HR intake', 'survey template', 'contract / SOW template', 'mail-…

No reviews yet
0 installs
0 views
view→install

Install

$ agentstack add skill-zhu1090093659-deepseek-pp-officecli-word-form

Open-source listing, not yet scanned by AgentStack. Follow the source repository for install instructions.

Security review

⚠ Flagged

1 finding(s); flagged for manual review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures
  • high Pipes remote content directly into a shell (remote code execution).

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Reliability & compatibility

Not yet reviewed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Officecli Word Form? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

OfficeCLI Word-Form Skill

This skill is INDEPENDENT, not a scene layer on docx. A form's payload — ` controls, legacy fields, mail-merge, documentProtection — is a distinct element class from docx's paragraph/heading/style primitives. Its QA is different too: docx's Delivery Gate cares about visual layout and live PAGE fields, this skill's cares about data plumbing (protection enforced / alias+tag / items injected / name ≤ 20 / no underscore anti-pattern). **Reverse handoff:** if the user's document has no fillable fields (report, letter, memo, thesis, proposal), route to officecli-docx` or a docx scene skill — don't use this one.

BEFORE YOU START (CRITICAL)

If officecli is not installed:

macOS / Linux

if ! command -v officecli >/dev/null 2>&1; then
    curl -fsSL https://d.officecli.ai/install.sh | bash
fi

Windows (PowerShell)

if (-not (Get-Command officecli -ErrorAction SilentlyContinue)) {
    irm https://d.officecli.ai/install.ps1 | iex
}

Verify: officecli --version

If officecli is still not found after first install, open a new terminal and run the verify command again.

If the install command above fails (e.g. blocked by security policy, no network access, or insufficient permissions), install manually — download the binary for your platform from https://github.com/iOfficeAI/OfficeCLI/releases — then re-run the verify command.

Help-First Rule

This skill teaches what a real form needs, not every CLI flag. When a prop / alias / enum is uncertain, consult help BEFORE guessing: officecli help docx [element] [--json] (e.g. sdt, formfield, field). Help is pinned to installed version — when this skill and help disagree, help wins. Every --prop X= below was verified against officecli help docx on v1.0.63.

Mental Model & Inheritance

A Word form is a .docx plus four OpenXML payload layers plain-docx skills do not touch: `** content controls (5 types: text / richtext / dropdown / combobox / date), **** legacy FormField (ONLY way to get a real checkbox on v1.0.63), **** complex fields (MERGEFIELD, REF, PAGEREF, SEQ, IF — template-time, not user-fill), and **documentProtection` (the lock that makes non-field text read-only in Word).

No inheritance from docx v2. docx's Delivery Gate (cover-fill %, live-PAGE check) does NOT apply — form QA is view forms + query sdt alias+tag + protectionEnforced.

Reverse handoff to docx. Route back to officecli-docx for reports / letters / memos / thesis / pitch decks / any document with no editable fields. Use this skill when the document's purpose is data capture or template merge.

Shell & Execution Discipline

One command at a time. Read output before the next. OfficeCLI is incremental — every add / set / remove immediately mutates the file. All recipes below use FILE=form.docx as a shell variable.

Three shell-escape layers:

  1. Quote every path with [N] — zsh/bash glob-expand brackets. officecli get "$FILE" /body/sdt[1] fails with no matches found. Correct: officecli get "$FILE" '/body/sdt[1]'.
  2. Single-quote any prop containing $"Total: $50,000" becomes "Total: ,000" after $50 variable expansion. Correct: 'Total: $50,000'.
  3. --after find: uses outer single quotes, never inner double quotes--after find:"Client Signature:" makes the quotes part of the search string; match fails. Correct: --after 'find:Client Signature:'.

WARNING: UNSUPPORTED (exit 2) is a silently-wrong element. The CLI created the element without the rejected prop — dropdown with no items, date with default format, SDT with no lock. Any UNSUPPORTED in your build log means your command was wrong: stop, rewrite to Path B (raw-set) or a separate set. Do not ship on top.

protection=forms is the LAST command. Not CLI-enforced — add / set / raw-set still run under any protection mode — but finishing with protection gives Word users a consistent locked experience on first open.

--after find: micro-playbook

--after find: matches the first occurrence. Bad anchor = wrong insertion location, expensive to debug. Three rules:

  1. Anchor must be globally unique. In bilingual contracts "甲方签字" matches both parties — use a unique phrase like "甲方签字(Service Provider)" or full English title.
  2. After insert, /body/p[last()] is unreliable — the find insertion changes ` child order. To continue operating on the new paragraph, read its real paraId: officecli query "$FILE" paragraph --json | jq -r '.data.results[-1].format.paraId'`.
  3. Chinese + full-width parens () match literally in find, but when unsure, officecli view "$FILE" text | grep -n "锚点" first to confirm the exact bytes in the file.
# Trap: first-match hits 甲方 only, 乙方 missed
officecli add "$FILE" /body --type sdt --after 'find:签字'

# Fix: two signatories, two unique anchors
officecli add "$FILE" /body --type sdt --prop alias=Party_A_Name --prop tag=party_a \
  --after 'find:甲方签字(Service Provider)'
PID_A=$(officecli query "$FILE" paragraph --json | jq -r '.data.results[-1].format.paraId')
officecli add "$FILE" "/body/p[@paraId='$PID_A']" --type sdt --prop alias=Party_A_Title --prop tag=party_a_title

Inline SDT via --after find: is added as a child of the matched paragraph, not as a new paragraph — use this when label + SDT must share a line.

What makes a real form (identity)

A real fillable form requires structured fields + document protection.

| Approach | Word user sees | CLI-readable | Real form? | |---|---|---|---| | SDT controls + protection=forms | Gray-bordered fields; rest locked | query sdt / view forms | YES | | FormField checkbox + protection=forms | Real clickable checkbox; rest locked | query formfield / view forms | YES (checkbox only) | | MERGEFIELD placeholders | «CustomerName» merged by downstream engine | query field | YES (template-time) | | Underscores ___ / blank lines | Visual-only; whole doc editable | No — no structured fields | NO |

Do not simulate fields with underscores. 姓名:_______________ produces zero structured data and leaks past every verification. Always use --type sdt or --type formfield.

Checkbox is formfield, NOT SDT. --type sdt --prop type=checkbox exits 1 (SDT type 'checkbox' is not implemented). Every checkbox in every recipe uses --type formfield --prop type=checkbox.

MERGEFIELD is a separate track. view forms lists SDT + formfield only; query field lists complex fields only. Two disjoint inventories; both valid in one file.

Requirements for Outputs (hard floor)

Every form must satisfy these — Delivery Gate enforces each as an executable check.

  1. protection=forms enforced (get $FILE /protectionEnforced=True).
  2. Every SDT has both alias + tag.
  3. Every dropdown/combobox has non-empty items=... in view forms.
  4. Every date SDT shows the intended format=....
  5. Every locked SDT shows lock=sdtLocked / contentLocked / sdtContentLocked as intended.
  6. Zero WARNING: UNSUPPORTED in build log.
  7. Zero type=checkbox on any SDT.
  8. Every formfield name ≤ 20 characters.
  9. Zero underscore-line / blank-line placeholders.
  10. Field types match user intent (short text / paragraph / fixed list / list+custom / date / boolean).

Three Paths (core decision)

CLI v1.0.63 exposes exactly four canonical props on SDT: {type, tag, alias, text}. Everything else — items, format, lock, placeholder, name, maxlength — is UNSUPPORTED at add-time and silently discarded. The skill therefore splits every SDT need into three paths. Pick the path before writing a single command.

Path A — Pure CLI (simple forms)

Use when: the field only needs a label, an initial text, and a type. Acceptable if dropdown/combobox items can be empty at first and dates can default to yyyy-MM-dd.

officecli add "$FILE" /body --type sdt \
  --prop type=text \
  --prop alias="Full Name" --prop tag=full_name \
  --prop text="Enter full name"
# Canonical follow-ups (not on add):
# officecli set "$FILE" '/body/sdt[N]' --prop lock=sdtlocked
# officecli set "$FILE" / --prop protection=forms

Path B — CLI + raw-set bridge (complex attrs)

Use when: dropdown/combobox needs options, or date needs a non-default format. raw-set is OfficeCLI's universal OpenXML fallback — officecli --help lists it as a top-level command.

# Step 1 — Path A skeleton (generates  automatically)
officecli add "$FILE" /body --type sdt \
  --prop type=dropdown --prop alias="Department" --prop tag=dept

# Step 2 — raw-set injects s
officecli raw-set "$FILE" /document \
  --xpath "//w:sdt[w:sdtPr/w:tag/@w:val='dept']/w:sdtPr/w:dropDownList" \
  --action append \
  --xml ''

Path C — Word template (beyond raw-set)

Use when: picture SDT (signature image), real SDT checkbox (type=checkbox exits 1), placeholderDocPart prompt text, grouped SDTs wrapping multiple paragraphs, or custom richtext appearance. These involve cross-part relationships or nesting beyond --prop reach.

# One-time in Word: Developer tab → Insert Content Control → Save as template.docx
cp templates/onboarding_with_signature.docx "$FILE"
officecli open "$FILE"
officecli view "$FILE" forms                 # inspect embedded controls + paths
officecli set "$FILE" '/body/sdt[@sdtId=3]' --prop text="Jane Smith"
officecli set "$FILE" / --prop protection=forms

Decision table

| Need | Path | Note | |---|---|---| | text / richtext SDT with default string | A | four canonical props cover it | | text SDT that must be locked | A + set lock | lock only takes effect via set, not add | | dropdown / combobox with options | B | raw-set append ` | | date SDT with non-default format | **B** | raw-set setattr w:dateFormat/@w:val | | real checkbox | **FormField** | --type formfield --prop type=checkbox (see §Legacy FormField) | | mail-merge placeholder | **MERGEFIELD** | --type field --prop fieldType=mergefield` (see §MERGEFIELD) | | signature picture, grouped SDT, placeholder part | C | build skeleton in Word, fill via CLI |

Quick Start — Path A + FormField (minimal intake form)

Two SDT text fields, one checkbox, protection. Paste and adapt; this is the smallest form worth shipping.

FILE=intake.docx
officecli close "$FILE" 2>/dev/null; rm -f "$FILE"   # preflight: clear stale resident / prior file (cold-start after CLI upgrade commonly leaks a resident)
officecli create "$FILE"
officecli open "$FILE"

officecli set "$FILE" / --prop title="Employee Onboarding Intake" \
  --prop docDefaults.font="Calibri" --prop docDefaults.fontSize="12pt"

officecli add "$FILE" /body --type paragraph \
  --prop text="Employee Onboarding Intake" --prop style=Heading1 \
  --prop size=20 --prop bold=true --prop spaceAfter=18pt

officecli add "$FILE" /body --type paragraph \
  --prop text="Full Name:" --prop size=11 --prop bold=true --prop spaceAfter=4pt
officecli add "$FILE" /body --type sdt --prop type=text \
  --prop alias="Full Name" --prop tag=full_name --prop text="Enter full name"

officecli add "$FILE" /body --type paragraph \
  --prop text="Start Date:" --prop size=11 --prop bold=true --prop spaceAfter=4pt
officecli add "$FILE" /body --type sdt --prop type=date \
  --prop alias="Start Date" --prop tag=start_date

officecli add "$FILE" /body --type paragraph \
  --prop text="Read and agree to employee handbook" --prop size=11 --prop spaceAfter=4pt
officecli add "$FILE" /body --type formfield \
  --prop type=checkbox --prop name=agree_handbook --prop checked=false

officecli set "$FILE" '/body/sdt[1]' --prop lock=sdtlocked
officecli set "$FILE" '/body/sdt[2]' --prop lock=sdtlocked
officecli set "$FILE" / --prop protection=forms
officecli close "$FILE"
officecli view "$FILE" forms

Path B — raw-set recipes

Three recipes cover almost every complex-attr need on SDT forms.

B1 — Dropdown items (append)

# Skeleton (Path A)
officecli add "$FILE" /body --type sdt --prop type=dropdown \
  --prop alias="Department" --prop tag=dept

# Inject items
officecli raw-set "$FILE" /document \
  --xpath "//w:sdt[w:sdtPr/w:tag/@w:val='dept']/w:sdtPr/w:dropDownList" \
  --action append \
  --xml ''

# Verify
officecli get "$FILE" '/body/sdt[1]'   # expect: type=dropdown items=Engineering,Finance,HR

Template. Swap ` / / only. xmlns:w=... is required on every root — raw-set does not inherit namespace prefixes. Chain multiple `s in one call; option order is preserved.

B2 — Combobox items (same as B1, different xpath tail)

officecli add "$FILE" /body --type sdt --prop type=combobox \
  --prop alias="Current Medication" --prop tag=current_med

officecli raw-set "$FILE" /document \
  --xpath "//w:sdt[w:sdtPr/w:tag/@w:val='current_med']/w:sdtPr/w:comboBox" \
  --action append \
  --xml ''

Only difference from B1: w:comboBox vs w:dropDownList in the xpath tail. Combobox lets the user type custom input; dropdown does not.

B3 — Date format (setattr)

officecli add "$FILE" /body --type sdt --prop type=date \
  --prop alias="Contract Start Date" --prop tag=contract_start

# Chinese: yyyy年MM月dd日
officecli raw-set "$FILE" /document \
  --xpath "//w:sdt[w:sdtPr/w:tag/@w:val='contract_start']/w:sdtPr/w:date/w:dateFormat" \
  --action setattr \
  --xml "w:val=yyyy年MM月dd日"

# US:    w:val=MM/dd/yyyy
# ISO:   w:val=yyyy-MM-dd  (already the default)
# Long:  w:val="MMMM d, yyyy"

officecli get "$FILE" '/body/sdt[N]'   # expect: type=date format=yyyy年MM月dd日

setattr replaces one attribute — do not quote the value inside --xml. Only w:val is touched; the `` wrapper is preserved.

raw-set actions & errors

| --action | Form use | |---|---| | append | Insert new child at end of target (B1, B2 — listItem) | | setattr | Change one attribute; --xml "key=value" (B3 — dateFormat/@val) | | replace | Replace entire target (rare — reset a full ` wrapper) | | remove` | Delete the target (clear options before re-populate) |

| Symptom | Fix | |---|---| | raw-set: 0 element(s) affected | XPath did not match. Check the tag value and whether the SDT is block or inline. Fall back to officecli raw $FILE /document to read the real XML. | | Error: prefix 'w' is not defined | Missing xmlns:w="http://schemas.openxmlformats.org/wordprocessingml/2006/main" on the fragment — every root element in --xml needs it. | | Items readback empty after append | ` must already exist (Path A type=dropdown ensures this). If absent, append has nowhere to insert. | | VALIDATION: N new error(s) introduced on same line as success | Your append introduced a schema-invalid child. Treat as stop-and-fix even though raw-set` exits 0. |

Path C — Word template workflow

For fields CLI cannot express (signature picture SDT, real SDT checkbox, placeholderDocPart prompt text, grouped SDTs, custom richtext styling), build the skeleton once in Word, then fill via CLI.

One-time in Word: File → Options → Customise Ribbon → Developer. Developer tab → Insert Picture / Check Box / Grouping Content Control → right-click → Properties → set Title (alias) + Tag. Save as template.docx.

Fill via CLI:

cp templates/onboarding_with_signature.docx "$FILE"
officecli open "$FILE"
officecli view "$FILE" forms                                    # see /body/... paths + sdtId values
officecli set "$FILE" '/body/sdt[@sdtId=3]' --prop text="Jane Smith"
officecli set "$FILE" / --prop protection=forms
officecli close "$FILE"

MERGEFIELD (data-driven track)

help docx field on v1.0.63 declares a fieldType enum of ~30 values including mergefield, ref, pageref, seq, if — all CLI-expressible with their typed props. MERGEFIELD coexists with SDT in the same file but is reported by query field on

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

  • Author: zhu1090093659
  • Source: zhu1090093659/deepseek-pp
  • License: Apache-2.0
  • Homepage: https://chromewebstore.google.com/detail/deepseek++/kdmpkkahkhdmdhfkdihkopikgcocbpbf?hl=zh-CN&authuser=0

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.