文件OCR解析

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed OCR helper that uploads user-selected files to a Deli Legal OCR API only when invoked, so its privacy risk is real but aligned with its purpose.

Install only if you are comfortable sending selected files to the Deli Legal OCR service or a configured compatible endpoint. Do not use it for confidential legal, financial, medical, or personal documents unless your policy permits that third-party processing, and review OCR results carefully before relying on amounts, dates, names, case numbers, invoices, or bank details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The code uploads the full user file to external OCR infrastructure via prepareUploadFile/PUT upload/fileParsing without any built-in notice, consent gate, or destination disclosure in this execution path. Because this skill is specifically used for scanned contracts, court documents, bills, and other potentially sensitive legal records, silent exfiltration to a third-party service creates a real confidentiality and compliance risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal