Back to skill

Security audit

arithmetic-orc

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Tencent Cloud math-OCR wrapper, with some privacy and packaging caveats but no evidence of hidden or malicious behavior.

Install only if you are comfortable sending math-problem images or image URLs to Tencent Cloud OCR and configuring Tencent Cloud credentials for the skill. Review the malformed plugin.json and pin dependency versions before production use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
使用 Node.js 脚本 `index.js` 调用腾讯云 `ArithmeticOCR` 接口,传入:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill metadata and user-facing instructions are entirely in Chinese and describe the behavior only in that language, with no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill sends user-provided image content or image URLs to Tencent Cloud’s external OCR API without any built-in disclosure, consent, or data-handling notice. This creates a privacy and trust risk because uploaded educational materials may contain sensitive student information, handwritten notes, or metadata, and users may reasonably assume processing is local unless told otherwise.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes an arithmetic OCR skill for recognizing math expressions in images, but does not indicate any need to access host environment secrets. Reading process environment variables introduces a credential-access capability beyond the user-facing OCR function and is not an obvious requirement of the declared skill scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description and parameter descriptions are entirely in Chinese, with no indication that the skill is region-specific or that users may choose another language. Under the policy rule, forcing a specific language without opt-in is a natural-language policy violation in manifest content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill accesses sensitive credential environment variables without any user-visible indication that external provider credentials are being used. While this is common operationally, in an agent-skill context it can obscure the fact that the skill relies on privileged secrets and a third-party backend, which weakens transparency and informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The package description is written entirely in Chinese ("腾讯云算式识别 Skill for OpenClaw") without indicating that other languages are supported or that the language choice is intentional. This can violate a language/locale policy if skills are expected to avoid forcing a specific language absent user opt-in or documented regional scope.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The dependency uses a caret range (^1.6.0), which allows installation of newer minor and patch releases that may change over time. This weakens build reproducibility and can unintentionally pull in a compromised or vulnerable upstream version during future installs.

Content

Scanner excerpt · package.json (reported line 7)May include surrounding context.

json
"description": "腾讯云算式识别 Skill for OpenClaw",
  "main": "index.js",
  "dependencies": {
    "axios": "^1.6.0"
  },
  "author": "yuejian chen",
  "license": "MIT"

Unverifiable Dependency: axios has 16 known advisory(ies) (CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
87% confidence
Finding

The manifest references axios without exact version pinning, while axios has multiple published advisories across versions. Because the allowed range is not fixed and no lockfile is shown, it is impossible to verify whether deployments will resolve to a safe release, creating supply-chain and known-vulnerability exposure.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
index.js:141