Back to skill

Security audit

invoice-data-extraction

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clearly disclosed third-party financial-document extraction integration, so users should treat uploaded documents as shared with that service but the behavior matches its stated purpose.

Install only if you are comfortable sending the selected financial documents and extraction instructions to Invoice Data Extraction and any service-controlled signed storage host it returns. Keep the API key in the environment or secret store, do not paste it into chat or files, and confirm that your organization allows third-party processing for bank statements, payslips, or other sensitive records.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Context Leakage

High
Category
Data Exfiltration
Confidence
85% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · SKILL.md (reported line 204)May include surrounding context.

md
## Limits and errors in one place

Files per extraction 6,000; PDF 150 MB and 5,000 pages; image 5 MB; upload session 2 GB; `task_name` 3 to 40 characters; results page up to 1,000 rows; output kept 90 days; download URLs valid 5 minutes. Rate limits per key per minute: uploads 600, status 120, submit and cancel and answers and output URL and delete 30, results and list and details and balance 60; a `429` carries `details.retry_after_seconds`. Every error body is `{ "success": false, "error": { "code", "message", "retryable", "details" } }` and the message says what to do next. The full tables: https://invoicedataextraction.com/docs/api.md.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The invocation description says to use the skill for extracting data from invoices, receipts, bills, bank statements, purchase orders, credit notes, payslips, or other financial documents whenever reading files directly would be unreliable or slow. This is very expansive and lacks explicit boundaries or negative examples, increasing the chance the skill is invoked for routine document-reading situations beyond its intended niche.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The referenced API endpoint is an external host, and the skill directs the agent to authenticate to it using a bearer token. That creates a real trust-boundary crossing for secrets and account data, which is security-relevant even if expected by the business function.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

  1. Check the key and the balance, which costs nothing:
bash
curl https://api.invoicedataextraction.com/v1/credits/balance \
  -H "Authorization: Bearer $INVOICE_DATA_EXTRACTION_API_KEY" -H "X-SDK-Name: skill"

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The referenced API endpoint is an external host, and the skill directs the agent to authenticate to it using a bearer token. That creates a real trust-boundary crossing for secrets and account data, which is security-relevant even if expected by the business function.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

  1. Check the key and the balance, which costs nothing:
bash
curl https://api.invoicedataextraction.com/v1/credits/balance \
  -H "Authorization: Bearer $INVOICE_DATA_EXTRACTION_API_KEY" -H "X-SDK-Name: skill"

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

This step initiates an upload session for user financial documents, including file names and sizes, as preparation for transmitting the actual content to a third-party service. Because the skill handles invoices, receipts, bank statements, and payslips, the context increases sensitivity: the transmitted data may contain highly confidential financial and personal information.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

1. Create the upload session with every file's exact size in bytes (1 to 6,000 files; PDFs up to 150 MB and 5,000 pages; images .jpg, .jpeg, .png up to 5 MB; 2 GB in all). Give each file the name the user knows it by, because file_name is what the Source File column shows.

bash
curl -X POST https://api.invoicedataextraction.com/v1/uploads/sessions \
  -H "Authorization: Bearer $INVOICE_DATA_EXTRACTION_API_KEY" \
  -H "X-SDK-Name: skill" -H "Content-Type: application/json" \
  -d '{ "upload_session_id": "sess_001", "files": [

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

Requesting signed upload URLs is a necessary precursor to sending raw document bytes to external storage. Although the skill notes that the API key is not sent to the storage host, the workflow still causes confidential document data to leave the local environment and be placed on infrastructure outside the agent host.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

2. Get the parts' upload URLs (up to 1,000 part numbers per request; each URL is valid for 15 minutes, so for a large file ask in batches just before uploading each batch):

bash
curl -X POST https://api.invoicedataextraction.com/v1/uploads/sessions/sess_001/parts \
  -H "Authorization: Bearer $INVOICE_DATA_EXTRACTION_API_KEY" \
  -H "X-SDK-Name: skill" -H "Content-Type: application/json" \
  -d '{ "file_id": "f1", "part_numbers": [1] }'

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This authenticated API call finalizes an externally uploaded file and is part of the same sensitive data-transfer pipeline. The risk is not remote code execution, but unauthorized or insufficiently disclosed transfer of sensitive financial documents and metadata to a third-party processor.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

3. Complete each file:

bash
curl -X POST https://api.invoicedataextraction.com/v1/uploads/sessions/sess_001/complete \
  -H "Authorization: Bearer $INVOICE_DATA_EXTRACTION_API_KEY" \
  -H "X-SDK-Name: skill" -H "Content-Type: application/json" \
  -d '{ "file_id": "f1", "parts": [ { "part_number": 1, "e_tag": "\"a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4\"" } ] }'

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This authenticated API call finalizes an externally uploaded file and is part of the same sensitive data-transfer pipeline. The risk is not remote code execution, but unauthorized or insufficiently disclosed transfer of sensitive financial documents and metadata to a third-party processor.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

3. Complete each file:

bash
curl -X POST https://api.invoicedataextraction.com/v1/uploads/sessions/sess_001/complete \
  -H "Authorization: Bearer $INVOICE_DATA_EXTRACTION_API_KEY" \
  -H "X-SDK-Name: skill" -H "Content-Type: application/json" \
  -d '{ "file_id": "f1", "parts": [ { "part_number": 1, "e_tag": "\"a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4\"" } ] }'

External Transmission

Medium
Category
Data Exfiltration
Confidence
99% confidence
Finding

The submission step sends extraction instructions and binds uploaded files into a processing job on a third-party service. In this skill’s context, that means potentially sensitive financial records are being processed externally, which is a real confidentiality and compliance risk if users are not clearly informed or if organizational policy forbids such transfer.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

4. Submit:

bash
curl -X POST https://api.invoicedataextraction.com/v1/extractions \
  -H "Authorization: Bearer $INVOICE_DATA_EXTRACTION_API_KEY" \
  -H "X-SDK-Name: skill" -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

Polling extraction status sends authenticated requests and may expose job metadata to the third-party service. While less sensitive than uploading the documents themselves, it remains part of an external workflow involving protected financial data and should be treated as a real trust-boundary crossing.

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

5. Wait with a held request. Use wait=25, which is shorter than the tool timeouts of the common harnesses; the maximum is 45:

bash
curl "https://api.invoicedataextraction.com/v1/extractions/$EXTRACTION_ID?wait=25" \
  -H "Authorization: Bearer $INVOICE_DATA_EXTRACTION_API_KEY" -H "X-SDK-Name: skill"

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

This step sends answers and clarifications about the user’s financial documents back to the third-party extraction service. Those answers may include contextual business rules or sensitive accounting interpretations, so the skill is transmitting not just files but also human-meaningful confidential context outside the local environment.

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

  • An answer names the question_id and gives one of: choice_id; choice_id with text beside it; text alone (1 to 1,000 characters, accepted on every question); or accept_recommended: true. Words beside a choice refine it: use them to say what the choice does not. Where the right answer differs by document type, say so in text ("on sales invoices the customer is the seller; on referral-fee invoices it is the firm paying the fee"), because one choice applies to every document.
bash
curl -X POST https://api.invoicedataextraction.com/v1/extractions/$EXTRACTION_ID/answers \
  -H "Authorization: Bearer $INVOICE_DATA_EXTRACTION_API_KEY" \
  -H "X-SDK-Name: skill" -H "Content-Type: application/json" \
  -d '{ "answers": [

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

Retrieving results from the external service is another authenticated trust-boundary crossing and may pull sensitive extracted financial data back into the agent environment. Although this is expected behavior, it is still security-relevant because it extends the lifecycle of sensitive data across systems and logs.

Content

Scanner excerpt · SKILL.md (reported line 144)May include surrounding context.

Completed. Read the rows as data, in pages of up to 1,000, passing next_offset back as offset until has_more is false:

bash
curl "https://api.invoicedataextraction.com/v1/extractions/$EXTRACTION_ID/results?limit=1000&offset=0" \
  -H "Authorization: Bearer $INVOICE_DATA_EXTRACTION_API_KEY" -H "X-SDK-Name: skill"

Static analysis

No suspicious patterns detected.