Back to skill

Security audit

GLM-OCR-SDK

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward OCR helper, but users should handle API keys and sensitive documents carefully because it uses a cloud service by default.

Install in an isolated environment, prefer a protected environment variable or secret manager over command-line --api-key or a repository .env file, avoid processing confidential documents with the cloud mode unless you are comfortable sending them to Zhipu, and consider self-hosted mode for sensitive material.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:25
Finding

Unpinned Third-Party Package Installation Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 25-27
Vulnerability Type: Unpinned dependency installation
Risk Level: Medium

Vulnerable Code

bash
# Install
pip install glmocr

Technical Analysis

The installation instruction retrieves the latest available glmocr package without specifying a reviewed version or verifying an integrity hash. Consequently, the code installed when a user follows this instruction can differ from the code that existed when the Skill was audited.

Python packages and their transitive dependencies can run code during installation and import. If the package publisher account, package index, release process, or a transitive dependency is compromised, a malicious package version could execute code in the user's environment. The instruction also does not identify an approved package index or provide a lock file containing hashes.

Attack Path

  1. An attacker compromises the package publisher, distribution channel, or a transitive dependency.
  2. The attacker publishes a malicious release under the package name resolved by pip.
  3. A user or agent follows the documented pip install glmocr instruction.
  4. pip downloads the attacker-controlled release because no version or hash is constrained.
  5. Malicious installation-time or runtime code executes with the privileges of the user running pip.
  6. That code may access files, environment variables, credentials, and documents available to the process.

Impact Assessment

Successful exploitation can result in arbitrary code execution under the installing user's privileges. The affected scope may include readable local files, OCR input documents, the ZHIPU_API_KEY environment variable, and other credentials accessible to that user. If installation is performed in a privileged environment, the impact increases accordingly.

Remediation
View remediation

Remediation Suggestions

  • Pin glmocr to a specifically reviewed version rather than installing the latest release.
  • Use a hash-locked requirements file, for example with --require-hashes.
  • Lock and audit all transitive dependencies.
  • Explicitly identify the trusted package index and disable unexpected supplemental indexes.
  • Install the package in an isolated, least-privileged virtual environment.
  • Add a controlled update process that requires security review before changing the pinned version.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:42
Finding

API Key Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 42; repeated at lines 106 and 183-184
Vulnerability Type: Secret exposure through process arguments and shell history
Risk Level: Medium

Vulnerable Code

bash
# CLI — pass API key directly (no env setup needed)
glmocr parse image.png --api-key sk-xxx

The same unsafe pattern is repeated later:

bash
glmocr parse image.png --api-key sk-xxx

Technical Analysis

The documentation recommends placing the API key directly in a command-line argument. Depending on the operating system and execution environment, command-line arguments may be exposed through process inspection utilities, system audit records, shell history, terminal logging, CI/CD logs, agent transcripts, or monitoring software.

Although the example uses a placeholder, users are explicitly instructed to replace it with a real credential. The SDK's support for the option does not make direct command-line secret transmission safe.

Attack Path

  1. A user replaces sk-xxx with a valid Zhipu API key and runs the documented command.
  2. The shell records the full command in its history, or the operating system exposes it in process metadata while the command is running.
  3. Another local user, administrator, log reader, monitoring system, or person with access to an agent transcript retrieves the command.
  4. The observer extracts the API key.
  5. The exposed key is used to make unauthorized API requests until it is revoked or expires.

Impact Assessment

Exploitation exposes the Zhipu API credential rather than directly granting operating-system privileges. An attacker may consume the victim's API quota, incur service charges, impersonate the credential holder to the extent permitted by the key, or access other API functionality authorized for that credential. The precise service-side scope depends on the permissions assigned to the key.

Remediation
View remediation

Remediation Suggestions

  • Remove examples that pass credentials through --api-key.
  • Recommend injection through a secret manager or a protected environment variable supplied outside the command transcript.
  • Ensure agents, CI systems, and wrappers redact API keys from logs and tool-call records.
  • If interactive entry is supported, read the secret from a non-echoing prompt or protected file descriptor.
  • Use narrowly scoped, short-lived credentials where supported.
  • Document immediate key rotation procedures for credentials accidentally entered on a command line.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:29
Finding

Plaintext API Key Written to an Unprotected .env File

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 29-32
Vulnerability Type: Insecure plaintext credential storage
Risk Level: Medium

Vulnerable Code

bash
# Set API key (once)
export ZHIPU_API_KEY=sk-xxx
# or add to .env file in working directory:
echo "ZHIPU_API_KEY=sk-xxx" >> .env

Technical Analysis

The instructions recommend appending a long-lived API key to a plaintext .env file in the current working directory. They do not require restrictive file permissions, verify the destination directory, or ensure that .env is excluded from source control, backups, build contexts, and uploaded artifacts.

The resulting permissions depend on the user's current umask and any pre-existing file permissions. In shared environments, the file may be readable by unintended local users. Because the location is the current working directory, it may also be created inside a repository and later committed or packaged accidentally.

Attack Path

  1. A user follows the instruction and writes a valid key to .env.
  2. The file is created with insufficiently restrictive permissions, or it resides in a repository, build context, synchronized directory, backup set, or artifact directory.
  3. Another local user or a recipient of the repository, backup, container image, or artifact reads the file.
  4. The observer extracts ZHIPU_API_KEY.
  5. The credential is used for unauthorized API requests until revoked or expired.

Impact Assessment

The vulnerability may disclose the Zhipu API key to local users or recipients of copied project data. An attacker can exercise the permissions assigned to that key, potentially consuming quota, generating charges, or invoking other authorized service operations. This issue does not by itself provide elevated local operating-system privileges.

Remediation
View remediation

Remediation Suggestions

  • Prefer an operating-system credential store, CI secret facility, or dedicated secret manager.
  • If a .env file must be used, create it with restrictive permissions, such as by setting umask 077, and enforce mode 0600.
  • Add .env and equivalent credential files to .gitignore, artifact exclusions, backup exclusions, and container build exclusions.
  • Warn users not to place the file in shared or publicly synchronized directories.
  • Avoid echo where shell tracing or transcript capture may record the secret; use a protected secret-provisioning mechanism.
  • Use narrowly scoped, short-lived keys and rotate any credential that may have been committed or uploaded.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

Set API key (once)

export ZHIPU_API_KEY=sk-xxx

or add to .env file in working directory:

echo "ZHIPU_API_KEY=sk-xxx" >> .env

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

Set API key (once)

export ZHIPU_API_KEY=sk-xxx

or add to .env file in working directory:

echo "ZHIPU_API_KEY=sk-xxx" >> .env

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

Set API key (once)

export ZHIPU_API_KEY=sk-xxx

or add to .env file in working directory:

echo "ZHIPU_API_KEY=sk-xxx" >> .env

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

Set API key (once)

export ZHIPU_API_KEY=sk-xxx

or add to .env file in working directory:

echo "ZHIPU_API_KEY=sk-xxx" >> .env

text

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

The documentation suggests appending the API key to a .env file in the working directory without warning about filesystem exposure, accidental source-control commits, workspace sharing, or agent access to local files. In shared or automated environments, storing plaintext credentials in the project directory can lead to credential leakage and downstream API abuse.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

Set API key (once)

export ZHIPU_API_KEY=sk-xxx

or add to .env file in working directory:

echo "ZHIPU_API_KEY=sk-xxx" >> .env

text

```python

Credential Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

Passing the API key as a CLI argument directly exposes it to process inspection, shell history, terminal recordings, and agent execution logs. Because this is a secret that authorizes paid cloud API access, leakage can quickly result in unauthorized usage and compromise of associated account resources.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
# CLI — pass API key directly (no env setup needed)
glmocr parse image.png --api-key sk-xxx

# Or load from a specific .env file
glmocr parse image.png --env-file /path/to/.env

# Or rely on env var / auto-discovered .env (set once, then omit)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill repeatedly states that document parsing uses Zhipu's cloud API but does not clearly warn that user-supplied files and extracted contents are transmitted to a third-party service. In an agent setting, this omission can cause sensitive PDFs, invoices, IDs, or internal documents to be sent off-host without informed consent or policy checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The examples recommend passing the API key directly on the command line, which can expose credentials via shell history, process listings, CI logs, telemetry, or agent traces. In automated agent environments this is especially risky because commands are often persisted verbatim for debugging and audit.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.