GLM-OCR-Table

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed OCR helper that sends user-selected files or URLs to Zhipu's GLM-OCR API to extract tables.

Install this only if you are comfortable using a Zhipu API key and sending the specific images, PDFs, or URLs you process to Zhipu's OCR service. Avoid using it on confidential, regulated, or sensitive business documents unless that external processing is approved.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill sends either local file contents or user-supplied remote file URLs to a third-party OCR API, but the CLI does not clearly warn users that their data will leave the local environment. In a document-processing skill, this matters because inputs may contain sensitive business, personal, or regulated data, creating confidentiality and compliance risk even though the transmission is part of intended functionality.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal