Back to skill

Security audit

CamScanner Official Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent CamScanner document tool, but it gives itself broad update and reporting behavior that users should review before installing.

Install only if you are comfortable with CamScanner processing your documents remotely, saving results to cloud by default unless you opt out, sending silent usage reports, and allowing the skill's updater to replace its CLI and Skill files from CamScanner's CDN. Prefer explicit local-only requests for sensitive documents and review updates through a trusted channel.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
Findings (42)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented behavior includes self-updating binaries and rewriting local skill content, which materially exceeds the stated purpose of document conversion and management. Self-modifying and self-updating behavior is especially dangerous in a skill context because it can change future execution semantics without a transparent review point.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented behavior includes self-updating binaries and rewriting local skill content, which materially exceeds the stated purpose of document conversion and management. Self-modifying and self-updating behavior is especially dangerous in a skill context because it can change future execution semantics without a transparent review point.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
After an upgrade changes the Skill, reread `SKILL.md` and the references needed for this task, then recheck capabilities and parameters. Record the actual CLI/S

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
## Operating Limits

1. **Do not leak credentials**: Tokens must only be obtained through `camscanner-cli auth login` and stored in the system keychain.
2. **File size limit**: Uploaded files must not exceed 40 MB.
3. **Supported image formats**: JPG, JPEG, PNG.
4. **Supported document formats**: PDF, TXT, Markdown.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/cloud-documents.md (reported line 41)May include surrounding context.

md
**Output format**: The CLI displays search results in a table.

**Agent display rules (mandatory)**: When presenting search results to the user, the agent **must** include at least the following four columns:

| Column | Source | Description |
|--------|--------|-------------|

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/setup.sh (reported line 3)May include surrounding context.

sh
#!/bin/sh
# camscanner-cli installer — downloads the platform-specific binary to a global PATH location.
# No Node.js or Go required. Only curl/wget needed.
#
# Usage:
#   bash scripts/setup.sh

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The usage example explicitly encourages curl ... | sh, which trains users to fetch and immediately execute remote code without prior inspection. If the CDN, DNS, TLS trust chain, or hosting account is compromised, arbitrary shell commands would run on the user's machine with the user's privileges.

Content

Scanner excerpt · scripts/setup.sh (reported line 7)May include surrounding context.

sh
#
# Usage:
#   bash scripts/setup.sh
#   curl -fsSL <CDN>/setup.sh | sh
#
# Environment variables (all optional):
#   CAMSCANNER_CLI_VERSION — version to install (default: read from SKILL.md or "latest")

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | sh chain causes downloaded content to be executed immediately, eliminating any opportunity for the user or tooling to inspect the script before execution. In an installer context this is especially dangerous because the script writes executables into a PATH directory, so a compromise can directly establish persistence or replace trusted commands.

Content

Scanner excerpt · scripts/setup.sh (reported line 7)May include surrounding context.

sh
#
# Usage:
#   bash scripts/setup.sh
#   curl -fsSL <CDN>/setup.sh | sh
#
# Environment variables (all optional):
#   CAMSCANNER_CLI_VERSION — version to install (default: read from SKILL.md or "latest")

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This script adds a self-update mechanism that downloads and replaces both the local CLI binary and skill files, which is outside the skill’s stated document-processing purpose. In this context, that creates a software supply-chain update path with filesystem write capability and persistent code replacement, substantially increasing the attack surface if the CDN, environment, or packaging process is compromised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script executes the newly downloaded binary ("${binPath}" --version) before establishing trust beyond a checksum fetched from the same remote source. Because the checksum file is also downloaded from the CDN, a compromise of that origin or redirection of CDN_BASE can result in arbitrary code execution during the validation step.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script implements an unattended self-update mechanism that downloads remote content and replaces both the local CLI binary and skill files. That capability is far outside the declared document-processing scope and materially expands the trust boundary: compromise of the CDN, release pipeline, or version metadata can lead to arbitrary code and prompt/skill replacement on the host.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/upgrade.sh (reported line 170)May include surrounding context.

sh
# ── Cleanup ─────────────────────────────────────────────────────────────────

cleanup() {
  rm -f "$TMP_DIR/camscanner-cli-"* 2>/dev/null
  rm -f "$TMP_DIR/camscanner-skill-"* 2>/dev/null
  rm -f "$TMP_DIR/checksums.txt" 2>/dev/null
  rm -rf "$TMP_DIR/skill" 2>/dev/null

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/upgrade.sh (reported line 171)May include surrounding context.

sh
cleanup() {
  rm -f "$TMP_DIR/camscanner-cli-"* 2>/dev/null
  rm -f "$TMP_DIR/camscanner-skill-"* 2>/dev/null
  rm -f "$TMP_DIR/checksums.txt" 2>/dev/null
  rm -rf "$TMP_DIR/skill" 2>/dev/null
  release_lock

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/upgrade.sh (reported line 172)May include surrounding context.

sh
cleanup() {
  rm -f "$TMP_DIR/camscanner-cli-"* 2>/dev/null
  rm -f "$TMP_DIR/camscanner-skill-"* 2>/dev/null
  rm -f "$TMP_DIR/checksums.txt" 2>/dev/null
  rm -rf "$TMP_DIR/skill" 2>/dev/null
  release_lock
}

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/upgrade.sh (reported line 173)May include surrounding context.

sh
rm -f "$TMP_DIR/camscanner-cli-"* 2>/dev/null
  rm -f "$TMP_DIR/camscanner-skill-"* 2>/dev/null
  rm -f "$TMP_DIR/checksums.txt" 2>/dev/null
  rm -rf "$TMP_DIR/skill" 2>/dev/null
  release_lock
}

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script marks the downloaded file executable and runs it to obtain a version string before installation. Executing a freshly downloaded binary is arbitrary code execution; checksum validation against a remotely downloaded checksums file does not prevent compromise if the distribution origin or release channel is malicious or breached.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill invokes shell commands, uses network access, and inspects environment state, but the manifest does not declare any tool scope or allowed-tools restrictions. That makes the execution surface broader than users and hosts can readily audit, increasing the risk of unintended command execution or networked side effects during normal use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest description says to use the skill for many generic intents such as format conversion, OCR, translation, editing, search/download/move, and folder management whenever the user mentions related concepts. This trigger scope is very broad and does not provide exclusion conditions or narrower activation constraints, increasing the chance of unintended invocation for ordinary document-related requests that may not specifically require CamScanner.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The usage reporting guidance sends the user's original natural-language input and executed commands, which may contain sensitive document descriptions, names, identifiers, or other private context unrelated to processing correctness. This creates unnecessary data exfiltration to a remote service and enlarges privacy and compliance risk.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 505)May include surrounding context.

md
- **Output path conflict protection**: The CLI silently overwrites existing files with `-o`; `pdf to-images -d` may also overwrite same-named page files in the directory. Before write operations, the agent **must** check whether the output path already exists. If it does:
  1. Prefer appending a numeric suffix, such as `output_1.jpg` or `output_2.jpg`.
  2. Or ask the user to confirm overwrite.
  3. Never overwrite an existing user file without confirmation.
- **Multiple file argument rules**: Do not pass multiple files with glob wildcards such as `*.jpg`. The agent **must**:
  1. Verify the requested file list and retain the user's explicit order; otherwise use natural sorting, where `page2` comes before `page10`.
  2. Pass each file as a full quoted path so spaces or special characters in filenames are safe.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/cloud-documents.md (reported line 127)May include surrounding context.

md
**Agent behavior rules**:
- `doc download` requires a `cs_doc_id` parameter (from the "Document ID" column in `doc search` results). **Without a cs_doc_id, downloading is not possible.**
- **Search results must be confirmed by the user before any operation**: even if only one document matches, the agent must present the result and wait for the user's explicit confirmation before downloading. **Do not** skip confirmation and auto-execute.
- **If the user has not provided a cs_doc_id and there are no search results in the current session**, the agent must first guide the user to run `doc search`, confirm the target document, then download.
  - Example: user says "download my contract" → Agent replies "Let me search for documents matching 'contract' first" → runs `doc search "contract"` → presents results for user confirmation → after confirmation, runs `doc download <cs_doc_id>`
- Office documents (doc_id suffix contains `_word1`, `_exce1`, `_pdfx0`, etc.) auto-keep their format; no need for `-f`

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/cloud-documents.md (reported line 127)May include surrounding context.

md
**Agent behavior rules**:
- `doc download` requires a `cs_doc_id` parameter (from the "Document ID" column in `doc search` results). **Without a cs_doc_id, downloading is not possible.**
- **Search results must be confirmed by the user before any operation**: even if only one document matches, the agent must present the result and wait for the user's explicit confirmation before downloading. **Do not** skip confirmation and auto-execute.
- **If the user has not provided a cs_doc_id and there are no search results in the current session**, the agent must first guide the user to run `doc search`, confirm the target document, then download.
  - Example: user says "download my contract" → Agent replies "Let me search for documents matching 'contract' first" → runs `doc search "contract"` → presents results for user confirmation → after confirmation, runs `doc download <cs_doc_id>`
- Office documents (doc_id suffix contains `_word1`, `_exce1`, `_pdfx0`, etc.) auto-keep their format; no need for `-f`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly routes users to a watermark removal operation without any warning, policy check, or limitation tied to ownership or authorization. That can facilitate copyright infringement, provenance tampering, or removal of attribution marks, and the surrounding workflow presents it as a normal enhancement action, which makes misuse easier.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The reference repeatedly promotes cloud-saving and remote OCR/translation/conversion flows without clearly warning that user files and extracted document contents may be uploaded to a third-party service. In a document-processing skill, users are likely to handle sensitive scans such as IDs, invoices, contracts, or receipts, so omission of a privacy/data-transmission warning can cause inadvertent disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The examples encourage use of -s to save PDF conversion outputs to the cloud, but they do not clearly warn that document contents are uploaded to a remote service. Because PDFs often contain sensitive personal, financial, legal, or corporate data, omission of this disclosure can cause users or downstream agents to exfiltrate documents outside expected local processing boundaries.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/setup.cjs:80

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/upgrade.cjs:74