Back to skill

Security audit

港澳台通行证识别与抽取(ADP)

Security checks for vulnerabilities and agentic risk

Overview

The skill’s document-extraction purpose is plausible, but its setup and bundled documentation expose users to unverified code execution and broader cloud document-processing capabilities than the named skill suggests.

Review this skill before installing. Use a pinned, verifiable CLI release instead of pipe-to-shell or unpinned global npm commands, avoid running installers as Administrator/root, and only process identity documents when you have consent and understand that files and extracted data may be sent to Laiye ADP cloud services. Keep API keys scoped and protected, and do not let an agent use the broader custom-app management commands unless you explicitly intend that administration.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:62
Finding

Mutable Remote Installer Scripts Are Executed Without Verification

Content
View full analysis
Remediation
View remediation
adp-init.sh" | sha256sum --check - less adp-init.sh bash ./adp-init.sh ``` 6. Provide equivalent signature and hash verification instructions for PowerShell. 7. Prefer a non-privileged, user-local installation and explicitly warn users not to run the installer as root or Administrator. 8. Document the files, network destinations, and configuration changes made by the installer. 9. If remote scripts remain available, pin the URL to a reviewed commit and still require integrity verification before execution. ]]>

T08 · Insecure Dependencies

Warning
Location
SKILL.md:57
Finding

Unpinned Global npm Package Installation Exposes a Supply-Chain Execution Path

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (20)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | bash chaining pattern is inherently dangerous because it transforms fetched network content directly into executable code with no validation boundary. In this skill context, the risk is more severe because users may trust the README for a narrowly scoped document-extraction skill and not expect system-level code execution guidance.

Content

Scanner excerpt · README-CN.md (reported line 29)May include surrounding context.

bash
# 方法 2: Shell 脚本(Linux / macOS,无 npm 环境时使用)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The curl ... | bash pattern is a classic command-chaining risk because it combines untrusted network content with immediate execution, eliminating opportunities for validation. In an agent or automation context, this is especially dangerous because it normalizes arbitrary code execution as part of setup and can be triggered non-interactively.

Content

Scanner excerpt · README.md (reported line 30)May include surrounding context.

bash
# Method 2: Shell script (Linux / macOS, when npm is not available)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documented commands allow creation, update, and deletion of custom applications plus AI-generated field design, which materially exceeds an extraction-only skill. In an agent setting, these administrative and generative capabilities expand the attack surface and could let a model alter configurations, create new processing behaviors, or access data flows not intended by the skill contract.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The curl ... | bash pattern is especially dangerous because it chains network retrieval directly into command execution with no verification, review, or integrity check. In the context of a skill that asks users to install tooling for processing identity documents, compromise of that install path could lead to full workstation compromise, credential theft, or tampering with sensitive document data.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

bash
# 方法 2: Shell 脚本(Linux / macOS,无 npm 环境时使用)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README describes a broad, general-purpose ADP document-processing CLI rather than a narrowly scoped Hong Kong/Macau permit extraction skill. This scope mismatch increases the chance that an agent or user will invoke capabilities far beyond the declared purpose, including generic document parsing and data handling that may not be expected under the skill’s manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The installation instructions recommend piping remotely fetched scripts directly into bash and PowerShell, which executes unverified code immediately. If the remote source, network path, or repository is compromised, users could suffer arbitrary code execution on their systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README instructs users to parse local documents and remote URLs using a cloud-backed service without clearly warning that document contents may be transmitted off-host. Because this skill targets identity documents, the omitted notice is especially risky: sensitive PII could be uploaded unexpectedly during agent execution.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented commands allow parsing and extraction of arbitrary local files, remote URLs, and Base64 input, which materially exceeds the stated permit-field extraction use case. In an agent context, this creates capability expansion and potential data-exfiltration risk because the skill can process arbitrary content and send it to an external cloud service.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Advertising custom application creation, update, and deletion introduces management capabilities unrelated to the stated extraction-only skill. In a delegated agent setting, these extra actions can let the skill alter server-side configurations or destroy resources, expanding blast radius beyond passive document processing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README presents a broad, general-purpose ADP document parsing/extraction CLI rather than a narrowly scoped skill for Hong Kong/Macau permit recognition. This scope mismatch can mislead an agent into invoking capabilities far beyond the declared purpose, increasing the risk of unintended document access, processing, or operational misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README advertises remote URL processing and local API-key/config storage without prominent warnings about transmitting sensitive identity documents to a public cloud service or protecting stored credentials. Because the skill targets identity documents, the absence of privacy and handling guidance increases the chance of accidental data exposure and insecure credential management.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to send highly sensitive identity-document images and extracted personal data to an external cloud service, but it does not prominently warn about data transmission, storage, retention, regional processing, or compliance obligations. Because the data includes government ID details and machine-readable code, users may unknowingly expose regulated personal information to a third party without informed consent or proper controls.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
99% confidence
Finding

This command fetches an external shell script from GitHub and executes it, creating a direct supply-chain and remote-code-execution risk. Users and agents have no integrity verification, pinning, or review step before running the script.

Content

Scanner excerpt · README-CN.md (reported line 29)May include surrounding context.

bash
# 方法 2: Shell 脚本(Linux / macOS,无 npm 环境时使用)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

External Script Fetching

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The installation instructions fetch and execute a remote shell script directly from the network. If the source, transport path, or upstream repository is compromised, users or agents could execute arbitrary code during installation with the current user’s privileges.

Content

Scanner excerpt · README.md (reported line 30)May include surrounding context.

bash
# Method 2: Shell script (Linux / macOS, when npm is not available)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

External Script Fetching

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The skill recommends fetching and executing a remote shell script directly from the internet. If the upstream repository, network path, or referenced script is compromised, users would execute attacker-controlled code immediately on their machine with their current privileges.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

bash
# 方法 2: Shell 脚本(Linux / macOS,无 npm 环境时使用)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest description claims extraction of a fixed set of key fields such as 姓名、姓名拼音、性别、出生日期、证件号码、签发日期、有效期至、签发机关, while the file's own documented result example and field table also include an additional field document_machine_readable_code (证件机读码). This indicates the skill does more than the top-level description states, albeit only slightly, by exposing an extra extracted field beyond the manifest's enumerated scope.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · license.md (reported line 10)May include surrounding context.

md
1. Licensing

1.1 Free Use and Distribution: The Licensor grants the Licensee a non-transferable, non-exclusive right to freely use, copy, publish, and distribute copies of the Product for non-commercial purposes. The aforementioned "non-commercial purposes" include, but are not limited to:
Personal learning, research, teaching, and evaluation.
Technical exchanges within academic institutions or open-source communities, non-profit projects.
Integration or demonstration in non-commercial products or services.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · license.md (reported line 14)May include surrounding context.

md
1. Licensing

1.1 Free Use and Distribution: The Licensor grants the Licensee a non-transferable, non-exclusive right to freely use, copy, publish, and distribute copies of the Product for non-commercial purposes. The aforementioned "non-commercial purposes" include, but are not limited to:
Personal learning, research, teaching, and evaluation.
Technical exchanges within academic institutions or open-source communities, non-profit projects.
Integration or demonstration in non-commercial products or services.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · license.md (reported line 22)May include surrounding context.

md
1. Licensing

1.1 Free Use and Distribution: The Licensor grants the Licensee a non-transferable, non-exclusive right to freely use, copy, publish, and distribute copies of the Product for non-commercial purposes. The aforementioned "non-commercial purposes" include, but are not limited to:
Personal learning, research, teaching, and evaluation.
Technical exchanges within academic institutions or open-source communities, non-profit projects.
Integration or demonstration in non-commercial products or services.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · license.md (reported line 32)May include surrounding context.

md
4. Disclaimer of Warranties

THE PRODUCT IS PROVIDED "AS IS", WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO: THE LICENSOR DOES NOT WARRANT THAT THE PRODUCT IS FREE FROM ERRORS, BUGS, WILL OPERATE PROPERLY, OR IS SUITABLE FOR A PARTICULAR PURPOSE; THE LICENSOR DOES NOT WARRANT THAT USE OF THE PRODUCT WILL NOT INFRINGE UPON THIRD-PARTY RIGHTS; THE LICENSOR SHALL NOT BE LIABLE TO THE LICENSEE OR ANY THIRD PARTY FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, OR PUNITIVE DAMAGES ARISING FROM THE USE OF THE PRODUCT.

5. Termination

Static analysis

No suspicious patterns detected.