fast-ocr

Security checks across malware telemetry and agentic risk

Overview

This is a local OCR skill for invoices and tickets; it handles sensitive documents but the reviewed code is purpose-aligned and shows no hidden network, credential, persistence, or destructive behavior.

Install only if you are comfortable processing the selected documents in the current agent environment. Treat OCR inputs and extracted text as sensitive, avoid unnecessary retention or logging, review OCR results before financial or compliance use, and consider pinning/verifying the OCR dependency and downloaded model source for business workflows.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The README encourages OCR extraction of invoices, travel tickets, and reimbursement documents, which commonly contain personal, financial, and tax identifiers, but it provides no privacy, retention, or handling guidance. In a skill designed to process sensitive documents, this omission increases the risk that users will upload, store, or share regulated data insecurely and assume the workflow is safe by default.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal