Back to skill

Security audit

Receipt Word Tool

Security checks for vulnerabilities and agentic risk

Overview

This looks like a legitimate local receipt-to-Word tool, but its model download instructions use weak verification for files that the OCR stack later loads.

Install only if you are comfortable processing financial screenshots locally and can manage the OCR models safely. Prefer verified model sources with pinned versions and SHA-256 checks, avoid --ssl-no-revoke unless you understand the reduced protection, and review amounts manually before submitting reimbursement documents.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/easyocr_offline_setup.md:8
Finding

Unverified ML Model Downloads from Mutable Third-Party URLs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
| `scripts/receipt_word_tool.py` | 完整可运行的 GUI 工具源码 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
| `scripts/receipt_word_tool.py` | 完整可运行的 GUI 工具源码 |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises functionality that necessarily reads local files (user-selected image folders) but does not declare any tool scope such as permissions or allowed-tools. This creates an authorization and transparency gap: a host system or reviewer cannot clearly determine or constrain file access behavior, increasing the risk of over-broad filesystem access if the skill is integrated into an agent runtime.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and the entire user-facing skill documentation are written only in Chinese, and the examples and usage text assume Chinese-language interaction. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not documented here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide explicitly recommends using curl --ssl-no-revoke to bypass certificate revocation checks when downloading OCR models. Disabling revocation validation weakens TLS assurance and can allow acceptance of certificates that should no longer be trusted, increasing the risk of man-in-the-middle delivery of tampered model files. In this skill context, the risk is more meaningful because the downloaded artifacts are executable-adjacent supply-chain inputs used by local OCR tooling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill's natural-language interface, labels, and stated purpose are entirely in Chinese, and the OCR reader is configured specifically for Chinese and English receipt extraction. There is no indication that users can opt into this locale/language constraint or choose another language, which matches the policy category for forced language/locale behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code contradicts the tool’s advertised offline/local behavior by lazily initializing EasyOCR in a way that may download model files on first use. This creates an unexpected network dependency and data-flow change in a document-processing tool, which can violate user trust, break offline assumptions, and expose the host to supply-chain or policy risks in restricted environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file contains user-facing instructions exclusively in Chinese, including the title and all operational guidance. Under the policy rule for natural-language violations, forcing a specific language without opt-in can be a locale-policy issue unless the regional constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Line L087 initializes EasyOCR with ['ch_sim', 'en'], which implies a fixed language/locale configuration. The document does not state that the tool is intentionally China/Chinese-specific or offer language selection, so this appears to force a locale choice without explicit user opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The stated purpose is to OCR payment screenshots and generate a formatted Word reimbursement document. Automatically launching the output file through os.startfile invokes an external application on the user's system, which is beyond the core OCR/layout function and is not declared in the manifest.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.