Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md 使用 Node.js 脚本 `index.js` 调用腾讯云 `ArithmeticOCR` 接口,传入:
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward Tencent Cloud math-OCR wrapper, with some privacy and packaging caveats but no evidence of hidden or malicious behavior.
Install only if you are comfortable sending math-problem images or image URLs to Tencent Cloud OCR and configuring Tencent Cloud credentials for the skill. Review the malformed plugin.json and pin dependency versions before production use.
Referenced artifact was not completely inspected
使用 Node.js 脚本 `index.js` 调用腾讯云 `ArithmeticOCR` 接口,传入:
Without declared permissions the skill's intent is opaque and cannot be validated.
The skill metadata and user-facing instructions are entirely in Chinese and describe the behavior only in that language, with no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
The skill sends user-provided image content or image URLs to Tencent Cloud’s external OCR API without any built-in disclosure, consent, or data-handling notice. This creates a privacy and trust risk because uploaded educational materials may contain sensitive student information, handwritten notes, or metadata, and users may reasonably assume processing is local unless told otherwise.
The manifest describes an arithmetic OCR skill for recognizing math expressions in images, but does not indicate any need to access host environment secrets. Reading process environment variables introduces a credential-access capability beyond the user-facing OCR function and is not an obvious requirement of the declared skill scope.
The skill description and parameter descriptions are entirely in Chinese, with no indication that the skill is region-specific or that users may choose another language. Under the policy rule, forcing a specific language without opt-in is a natural-language policy violation in manifest content.
The skill accesses sensitive credential environment variables without any user-visible indication that external provider credentials are being used. While this is common operationally, in an agent-skill context it can obscure the fact that the skill relies on privileged secrets and a third-party backend, which weakens transparency and informed consent.
The package description is written entirely in Chinese ("腾讯云算式识别 Skill for OpenClaw") without indicating that other languages are supported or that the language choice is intentional. This can violate a language/locale policy if skills are expected to avoid forcing a specific language absent user opt-in or documented regional scope.
The dependency uses a caret range (^1.6.0), which allows installation of newer minor and patch releases that may change over time. This weakens build reproducibility and can unintentionally pull in a compromised or vulnerable upstream version during future installs.
"description": "腾讯云算式识别 Skill for OpenClaw",
"main": "index.js",
"dependencies": {
"axios": "^1.6.0"
},
"author": "yuejian chen",
"license": "MIT"
The manifest references axios without exact version pinning, while axios has multiple published advisories across versions. Because the allowed range is not fixed and no lockfile is shown, it is impossible to verify whether deployments will resolve to a safe release, creating supply-chain and known-vulnerability exposure.
Detected: suspicious.env_credential_access