Back to skill

Security audit

OCR Space: Free OCR API

Security checks for vulnerabilities and agentic risk

Overview

This OCR skill appears to do what it claims, but it uploads images to OCR.space and has a local compressed-file overwrite/delete risk that users should review before installing.

Use this only for images you are comfortable sending to OCR.space. Avoid sensitive or regulated documents unless the external sharing is acceptable, and run it with ordinary user privileges in directories without valuable matching *_compressed.jpg files. The publisher should add explicit upload disclosure and replace the predictable compressed file path with a secure temporary file that is cleaned up reliably.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
ocr_space.py:67
Finding

Predictable Compression File Path Enables Arbitrary File Overwrite

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises and documents a network-backed OCR capability but does not declare any explicit tool scope or permissions. This creates a transparency and governance gap: users or orchestration systems may invoke the skill without realizing it performs external network access, which can lead to unintended data exfiltration of image contents to a third-party service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description says it performs OCR but does not clearly warn that provided images are uploaded to the third-party OCR.space service. This is dangerous because users may pass screenshots, IDs, receipts, or other sensitive images under the assumption processing is local, resulting in unintended disclosure of personal, confidential, or regulated data to an external party.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The code is explicitly designed to transmit image data to an external OCR API, which creates a real data egress path to a third party. In the context of an OCR skill, this is expected functionality, but it still becomes security-relevant when handling confidential images because sensitive content leaves the local trust boundary.

Content

Scanner excerpt · ocr_space.py (reported line 30)May include surrounding context.

python
import json
import base64

API_URL = "https://api.ocr.space/parse/image"
API_KEY = "helloworld"  # 免费测试 key

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script sends user-provided image contents to the third-party OCR.space service, but it does not present an explicit runtime warning or consent step about external data sharing. Images often contain sensitive personal or business information, so silent transmission to an external API can cause privacy and compliance issues in agent environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The documentation and function signature set the default language to chs, making Simplified Chinese the default behavior unless the user supplies another language code. This is a locale/language preference baked in by default rather than chosen by the user.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest description says the skill calls the OCR.space API to recognize text in images, which implies network OCR behavior. However, the implementation additionally rewrites oversized images into new local JPEG files as part of preprocessing, which is a file-modifying behavior not conveyed by the description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.