External Transmission
- Category
- Data Exfiltration
- Confidence
- 96% confidence
- Finding
This step uploads a local image file to an external third-party service, which is a genuine data exfiltration boundary even though it is the core purpose of the skill. The risk is mainly privacy and compliance related: users may unintentionally send sensitive documents, IDs, invoices, or other confidential images off-device for OCR and conversion.
- Content
bash BASE="https://ai-tools.camscanner.com" IN_FILE_ID=$(curl -sS -X POST "$BASE/v1/tools/upload_file/execute" \ -H "Content-Type: application/octet-stream" \ --data-binary "@/path/to/image.png" | jq -r '.tool_result.data.file_id')
