Ocr Web Service

Security checks across malware telemetry and agentic risk

Overview

The skill appears to provide a disclosed OCR/API integration, with the main risk being that document contents may be sent to an external service when used.

Install only if you are comfortable sending selected OCR inputs and related metadata to the external OCR/API provider. Avoid using it on highly sensitive documents unless the provider, account permissions, and retention terms meet your needs, and prefer predefined actions over raw proxy requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly documents a generic proxy capability that can send arbitrary requests to the external OCR service, but it does not require user confirmation, scope restrictions, or warnings about transmitting sensitive document contents and metadata. In a document/OCR context, this increases the risk of unintended exfiltration of sensitive files, extracted text, or identifiers to a third-party service through broad agent-directed API access.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal