Back to skill

Security audit

营业执照识别与抽取(ADP)

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real Laiye ADP cloud document-extraction skill, but its package exposes broader document processing and app-management authority than a business-license-only skill needs.

Install only if you intend to use Laiye ADP as a third-party cloud processor for sensitive business-license documents. Prefer npm or verified release downloads over pipe-to-shell installation, use a dedicated/restricted ADP API key, avoid broad folders or unrelated documents, and confirm your policy allows uploading business-license data and extracted identifiers to Laiye ADP.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The README documents a broad, general-purpose ADP CLI rather than a narrowly scoped business-license recognition skill. This scope mismatch can cause an agent to invoke capabilities far beyond the advertised purpose, increasing attack surface and enabling unintended data handling or tool use in contexts that expected a constrained extractor.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The documentation exposes custom application creation, update, deletion, and AI-generation features that are unrelated to simple business-license extraction. In an agent setting, these management commands materially expand what the tool can do, creating opportunities for unauthorized configuration changes, misuse of broader platform functionality, or accidental destructive actions.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The README presents this skill as a front-end to a broad, general-purpose ADP CLI that can parse arbitrary local files, fetch remote URLs, manage apps, and perform unrelated document workflows. That materially exceeds the declared business-license-only purpose, increasing the chance that an agent or user invokes overly broad capabilities and sends unintended data to the service.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
Advertising custom app creation and management inside a skill that claims fixed business-license extraction introduces unauthorized extensibility. This can let the skill be repurposed for arbitrary document extraction tasks beyond the user's expectations and beyond the declared trust boundary.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
Lifecycle management for custom extraction apps is an unjustified privileged capability in a business-license recognition skill. It enables creating, modifying, and deleting extraction configurations, which expands the attack surface from simple recognition into platform administration and arbitrary workflow reconfiguration.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The '注意事项' section contains copy-paste content for driver's licenses, including mismatched PII examples and field names, which conflicts with the stated business-license purpose. This can cause an agent or operator to apply the wrong data-handling rules, leading to improper masking, retention, or downstream processing of sensitive business-license data.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The README encourages processing remote URLs through a cloud service but does not clearly warn that documents may contain sensitive personal or corporate data transmitted to third-party infrastructure. Users or agents may unknowingly submit confidential files, creating privacy, compliance, and data residency risks.

Missing User Warnings

Low
Confidence
80% confidence
Finding
The batch-processing section describes writing extracted results and error files to disk without warning that outputs may contain sensitive business-license data or API-derived results. This can lead to inadvertent local exposure through shared workstations, insecure directories, backups, or source-control commits.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The README shows commands that process local files and remote URLs through a public cloud ADP service but does not clearly warn that document contents and URLs may be transmitted off-host for cloud processing. In a document-handling skill, that omission is security-relevant because users may unknowingly submit sensitive business records or personal information to an external service.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill instructs users to send document images and extracted business-license fields to a remote third-party ADP service, but it does not prominently warn that source documents and PII/business data leave the local environment. Because the skill processes identifiers, names, and addresses, lack of explicit disclosure can cause unintentional sensitive-data exfiltration and compliance/privacy issues.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.