T09 · Insecure Skill Coding Practices
- Location
ocr_space.py:67- Finding
Predictable Compression File Path Enables Arbitrary File Overwrite
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This OCR skill appears to do what it claims, but it uploads images to OCR.space and has a local compressed-file overwrite/delete risk that users should review before installing.
Use this only for images you are comfortable sending to OCR.space. Avoid sensitive or regulated documents unless the external sharing is acceptable, and run it with ordinary user privileges in directories without valuable matching *_compressed.jpg files. The publisher should add explicit upload disclosure and replace the predictable compressed file path with a secure temporary file that is cleaned up reliably.
ocr_space.py:67Predictable Compression File Path Enables Arbitrary File Overwrite
The skill advertises and documents a network-backed OCR capability but does not declare any explicit tool scope or permissions. This creates a transparency and governance gap: users or orchestration systems may invoke the skill without realizing it performs external network access, which can lead to unintended data exfiltration of image contents to a third-party service.
The skill description says it performs OCR but does not clearly warn that provided images are uploaded to the third-party OCR.space service. This is dangerous because users may pass screenshots, IDs, receipts, or other sensitive images under the assumption processing is local, resulting in unintended disclosure of personal, confidential, or regulated data to an external party.
The code is explicitly designed to transmit image data to an external OCR API, which creates a real data egress path to a third party. In the context of an OCR skill, this is expected functionality, but it still becomes security-relevant when handling confidential images because sensitive content leaves the local trust boundary.
import json
import base64
API_URL = "https://api.ocr.space/parse/image"
API_KEY = "helloworld" # 免费测试 key
The script sends user-provided image contents to the third-party OCR.space service, but it does not present an explicit runtime warning or consent step about external data sharing. Images often contain sensitive personal or business information, so silent transmission to an external API can cause privacy and compliance issues in agent environments.
The documentation and function signature set the default language to chs, making Simplified Chinese the default behavior unless the user supplies another language code. This is a locale/language preference baked in by default rather than chosen by the user.
The manifest description says the skill calls the OCR.space API to recognize text in images, which implies network OCR behavior. However, the implementation additionally rewrites oversized images into new local JPEG files as part of preprocessing, which is a file-modifying behavior not conveyed by the description.
No suspicious patterns detected.