Back to skill

Security audit

daily-scan

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent local document-scanning helper, with ordinary privacy and file-handling risks but no evidence of deception, exfiltration, persistence, or destructive intent.

Install only if you are comfortable with document photos and searchable PDFs being stored locally. Use a private scan folder, avoid shared writable directories, and delete originals or generated files yourself when they contain sensitive information you no longer want retained.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/build_searchable_pdf.py:98
Finding

Predictable Temporary PDF and Image Paths Permit File Overwrite and Symlink Attacks

Content
View full analysis
` - `temp_image.pdf` It does not verify whether these paths already exist, whether they are symbolic links, or whether the output directory is writable by other users. The file-writing operations are also not performed with exclusive creation semantics. If an untrusted user can write to the selected output directory, that user can pre-create one of these predictable paths as a symbolic link to another file writable by the scanning process. When OpenCV, Pillow, or OCRmyPDF writes to the path, the linked target may be overwritten. Predictable paths also allow concurrent executions to overwrite or consume each other's intermediate files. The generated final filename is similarly not checked for collisions, so two documents producing the same date and OCR headline may overwrite or conflict with one another. ### Attack Path 1. An attacker obtains write access to a shared scan output directory. 2. The attacker predicts that the script will create `temp_image.pdf` or `enhanced_`. 3. The attacker creates that path as a symbolic link to another file writable by the victim process. ...[truncated 1019 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/build_searchable_pdf_paddle.py:96
Finding

Predictable Enhanced-Image Paths in PaddleOCR Builder Permit File Overwrite

Content
View full analysis
` as a symbolic link to another writable target. 4. The victim invokes the PaddleOCR builder with that output directory and input image. 5. `cv2.imwrite()` follows or replaces the predictable path without validating it. 6. The target is overwritten with the enhanced document image. For a concurrency attack, two scan jobs can process source files with the same basename in the same output directory, causing their intermediate images and OCR results to interfere. ### Impact Assessment The attacker can ac ...[truncated 512 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill explicitly depends on local helper scripts and shell-invoked OCR tooling, but it does not declare any tool scope or allowed-tools boundary. That creates an authorization and review gap: a host agent may permit shell execution more broadly than intended, increasing the chance of unsafe command use or unexpected file-system access during document processing and retrieval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill processes sensitive document images and states that it will save processed PDFs while preserving the original photos, but it does not provide a clear user-facing warning or consent cue. This can lead to unintentional retention of personal, financial, or identity documents on local storage, creating privacy and data exposure risk if the device or storage path is later accessed by others.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The function defaults OCR to 'kor+eng', and the OCRmyPDF invocation also forces 'kor+eng', which imposes a specific language/locale choice. The file does not offer user opt-in or configuration for language selection, nor does it document a region-specific justification for this constraint.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/build_searchable_pdf.py (reported line 31)May include surrounding context.

python
def run_ocr(image_path: str, lang: str = 'kor+eng') -> str:
    result = subprocess.run(
        ['tesseract', image_path, 'stdout', '-l', lang, '--psm', '6'],
        capture_output=True,
        text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/build_searchable_pdf.py (reported line 73)May include surrounding context.

python
def apply_ocrmypdf(input_pdf: str, output_pdf: str) -> str:
    result = subprocess.run(
        ['ocrmypdf', '--force-ocr', '-l', 'kor+eng', input_pdf, output_pdf],
        capture_output=True,
        text=True,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code forces a specific language locale via lang='korean', which is a natural-language policy concern when no opt-in or configurability is provided. This can violate language/locale choice expectations because users processing non-Korean documents are not given a way to select another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file states that OCR runs in Korean and English, and later says the OCR language defaults to Korean plus English. This is a locale/language policy concern because it imposes a language configuration without presenting user choice or clearly documenting a justified region-specific restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code creates directories and writes enhanced images and PDF files, including a temporary PDF and a final OCR output, but provides no user-facing notice beyond the usage string. For a code file, file writes should have some visible disclosure such as a print/log message, comment, or documented warning, especially since the script also auto-selects an output location when 'AUTO' is used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code performs file creation as part of image enhancement and later generates a searchable PDF, but there is no confirmation prompt or explicit disclosure beyond the usage string. For a code-file audit, file writes that affect user data should have some visible warning unless clearly disclosed; this script does not communicate that intermediate enhanced files will be created in the output directory.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.