T08 · Insecure Dependencies
- Location
references/easyocr_offline_setup.md:8- Finding
Unverified ML Model Downloads from Mutable Third-Party URLs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This looks like a legitimate local receipt-to-Word tool, but its model download instructions use weak verification for files that the OCR stack later loads.
Install only if you are comfortable processing financial screenshots locally and can manage the OCR models safely. Prefer verified model sources with pinned versions and SHA-256 checks, avoid --ssl-no-revoke unless you understand the reduced protection, and review amounts manually before submitting reimbursement documents.
references/easyocr_offline_setup.md:8Unverified ML Model Downloads from Mutable Third-Party URLs
Referenced artifact was not completely inspected
| `scripts/receipt_word_tool.py` | 完整可运行的 GUI 工具源码 |
Referenced artifact was not completely inspected
| `scripts/receipt_word_tool.py` | 完整可运行的 GUI 工具源码 |
The skill advertises functionality that necessarily reads local files (user-selected image folders) but does not declare any tool scope such as permissions or allowed-tools. This creates an authorization and transparency gap: a host system or reviewer cannot clearly determine or constrain file access behavior, increasing the risk of over-broad filesystem access if the skill is integrated into an agent runtime.
The manifest description and the entire user-facing skill documentation are written only in Chinese, and the examples and usage text assume Chinese-language interaction. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not documented here.
The guide explicitly recommends using curl --ssl-no-revoke to bypass certificate revocation checks when downloading OCR models. Disabling revocation validation weakens TLS assurance and can allow acceptance of certificates that should no longer be trusted, increasing the risk of man-in-the-middle delivery of tampered model files. In this skill context, the risk is more meaningful because the downloaded artifacts are executable-adjacent supply-chain inputs used by local OCR tooling.
The skill's natural-language interface, labels, and stated purpose are entirely in Chinese, and the OCR reader is configured specifically for Chinese and English receipt extraction. There is no indication that users can opt into this locale/language constraint or choose another language, which matches the policy category for forced language/locale behavior.
The code contradicts the tool’s advertised offline/local behavior by lazily initializing EasyOCR in a way that may download model files on first use. This creates an unexpected network dependency and data-flow change in a document-processing tool, which can violate user trust, break offline assumptions, and expose the host to supply-chain or policy risks in restricted environments.
This markdown file contains user-facing instructions exclusively in Chinese, including the title and all operational guidance. Under the policy rule for natural-language violations, forcing a specific language without opt-in can be a locale-policy issue unless the regional constraint is explicitly documented and justified.
Line L087 initializes EasyOCR with ['ch_sim', 'en'], which implies a fixed language/locale configuration. The document does not state that the tool is intentionally China/Chinese-specific or offer language selection, so this appears to force a locale choice without explicit user opt-in.
The stated purpose is to OCR payment screenshots and generate a formatted Word reimbursement document. Automatically launching the output file through os.startfile invokes an external application on the user's system, which is beyond the core OCR/layout function and is not declared in the manifest.
No suspicious patterns detected.