Back to skill

Security audit

组织机构代码证识别与抽取(ADP)

Security checks for vulnerabilities and agentic risk

Overview

This cloud document-extraction skill is broadly useful, but its installation and documentation give it more risky authority than a certificate-only extractor should need.

Review before installing. Use this only if you trust Laiye ADP and are allowed to send certificate images and extracted business data to its cloud service. Prefer a pinned, verifiable release or reviewed package install instead of curl-to-shell or PowerShell Invoke-Expression, protect the ADP API key, and do not allow the agent to use custom-app management or arbitrary document-processing commands unless you explicitly intend that broader access.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:62
Finding

Mutable Remote Installation Scripts Are Downloaded and Executed Without Verification

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:57
Finding

Unpinned Global npm Dependency Installation Creates Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (22)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The explicit | bash pattern is a classic chaining abuse primitive: it combines network retrieval with immediate interpreter execution, eliminating review and integrity checks. In a skill context, this is especially risky because agents or users may copy-paste the command verbatim, leading to one-step remote code execution.

Content

Scanner excerpt · README-CN.md (reported line 29)May include surrounding context.

bash
# 方法 2: Shell 脚本(Linux / macOS,无 npm 环境时使用)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README describes a broad, general-purpose ADP CLI with capabilities spanning arbitrary document parsing, extraction, automation workflows, and agent use, which materially exceeds the narrowly declared skill purpose of organization-code-certificate recognition and extraction. This scope mismatch is dangerous because an agent or user may grant the skill far broader trust and operational latitude than intended, enabling unintended data access, transmission, or task execution outside the declared business function.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The explicit curl ... | bash pattern is a classic command-chaining anti-pattern that executes unverified remote content directly in a shell. In the context of an AI skill README, this is especially risky because users or agents may copy it verbatim, leading to immediate arbitrary code execution if the fetched content is malicious or altered.

Content

Scanner excerpt · README.md (reported line 30)May include surrounding context.

bash
# Method 2: Shell script (Linux / macOS, when npm is not available)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Including custom application creation, update, and deletion commands in a certificate-recognition skill gives the skill mutation and lifecycle-management capabilities unrelated to simple field extraction. In an agent context, this broadens the attack surface from passive document processing to changing server-side configurations and apps, which could be abused to alter extraction logic, destroy configurations, or pivot into wider platform administration.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The specific use of curl ... | bash creates a high-risk command-chaining pattern where untrusted network content is immediately executed. This makes compromise easy to weaponize and gives users no chance to validate the retrieved content before code execution.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

bash
# 方法 2: Shell 脚本(Linux / macOS,无 npm 环境时使用)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README describes a broad, general-purpose ADP CLI for arbitrary document parsing, extraction, app management, and agent use, which does not match the manifest’s narrow claim of a skill limited to Chinese organization code certificate recognition. This scope mismatch is dangerous because users or agents may grant broader trust, capabilities, and data access than intended, enabling misuse of the skill as a generic document-processing wrapper rather than a constrained extractor.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README instructs users to process remote URLs and export results locally, but does not clearly warn that document contents may be transmitted to a third-party cloud service or persisted to disk. This creates privacy and compliance risk, especially for sensitive business documents, because operators may unknowingly exfiltrate data externally or leave extracted results in local files and directories.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README advertises custom application creation, update, deletion, and AI-generated schema features that materially exceed the stated purpose of certificate recognition/extraction. In an agent skill context, exposing undocumented broader functionality increases the chance of capability confusion and abuse, allowing the skill to be repurposed for arbitrary extraction workflows beyond what operators believe they approved.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README instructs users to process local and remote documents and export results, but does not clearly warn that document contents are transmitted to a public cloud service and that extracted outputs may be written to local disk. For document-processing skills handling business records and certificates, this omission can lead to accidental disclosure of sensitive data and unsafe storage practices by users or downstream agents.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Support for processing arbitrary remote URLs is broader than the declared certificate-extraction use case and enables the skill to fetch or submit documents from external locations outside a controlled local workflow. In practice this can increase data exfiltration, misuse of third-party content, and unintended processing of sensitive remote resources, especially when an agent follows untrusted inputs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs users to upload certificate images and extracted data to an external ADP cloud service but does not clearly and prominently disclose that documents leave the local environment or explain the privacy/compliance implications. Because these files may contain organization identifiers, addresses, and legal representative information, users could inadvertently transmit sensitive data to a third party without informed consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file claims to document a skill for 组织机构代码证 extraction, but these sections instruct the user to identify and cache an app for 开户许可证 instead. This is an active contradiction in the documentation about which extraction app should be used, and could cause the agent or user to invoke the wrong capability.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Several later sections switch from 组织机构代码证 to 营业执照, 开户许可证, and 驾驶证 when describing pricing, app_id reuse, PII handling, and empty-field behavior. These are direct documentation contradictions that blur the intended skill and could cause misuse of the wrong extraction app or wrong data-handling assumptions.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The README recommends installing via a shell command that fetches a remote script directly from GitHub and executes it. This is dangerous because any compromise of the repository, branch, network path, or referenced script immediately becomes arbitrary code execution on the user’s machine.

Content

Scanner excerpt · README-CN.md (reported line 29)May include surrounding context.

bash
# 方法 2: Shell 脚本(Linux / macOS,无 npm 环境时使用)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

External Script Fetching

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The README recommends installing via a shell pipeline that fetches a remote script and executes it immediately. This is dangerous because compromise of the upstream source, repository, CDN path, or transport endpoint would result in arbitrary code execution on the user's machine with the privileges of the invoking user.

Content

Scanner excerpt · README.md (reported line 30)May include surrounding context.

bash
# Method 2: Shell script (Linux / macOS, when npm is not available)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The description and operational instructions are presented entirely in Chinese, with no indication that users may choose another language or locale. Under the language/locale policy rule, forcing a single language without opt-in can be a natural-language policy concern unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The skill recommends installing software by fetching a remote script from GitHub and executing it directly via the shell. This bypasses review and integrity verification; if the script source, repository, network path, or upstream account is compromised, arbitrary code will run on the user's machine with the user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

bash
# 方法 2: Shell 脚本(Linux / macOS,无 npm 环境时使用)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The text says the skill returns '6个关键字段' and '以下6个字段', but the JSON example and field table enumerate 8 fields. This is not merely incomplete documentation; it actively contradicts the described output contract and can mislead downstream integrators about the skill's actual behavior.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · license.md (reported line 10)May include surrounding context.

md
1. Licensing

1.1 Free Use and Distribution: The Licensor grants the Licensee a non-transferable, non-exclusive right to freely use, copy, publish, and distribute copies of the Product for non-commercial purposes. The aforementioned "non-commercial purposes" include, but are not limited to:
Personal learning, research, teaching, and evaluation.
Technical exchanges within academic institutions or open-source communities, non-profit projects.
Integration or demonstration in non-commercial products or services.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · license.md (reported line 14)May include surrounding context.

md
1. Licensing

1.1 Free Use and Distribution: The Licensor grants the Licensee a non-transferable, non-exclusive right to freely use, copy, publish, and distribute copies of the Product for non-commercial purposes. The aforementioned "non-commercial purposes" include, but are not limited to:
Personal learning, research, teaching, and evaluation.
Technical exchanges within academic institutions or open-source communities, non-profit projects.
Integration or demonstration in non-commercial products or services.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · license.md (reported line 22)May include surrounding context.

md
1. Licensing

1.1 Free Use and Distribution: The Licensor grants the Licensee a non-transferable, non-exclusive right to freely use, copy, publish, and distribute copies of the Product for non-commercial purposes. The aforementioned "non-commercial purposes" include, but are not limited to:
Personal learning, research, teaching, and evaluation.
Technical exchanges within academic institutions or open-source communities, non-profit projects.
Integration or demonstration in non-commercial products or services.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · license.md (reported line 32)May include surrounding context.

md
4. Disclaimer of Warranties

THE PRODUCT IS PROVIDED "AS IS", WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO: THE LICENSOR DOES NOT WARRANT THAT THE PRODUCT IS FREE FROM ERRORS, BUGS, WILL OPERATE PROPERLY, OR IS SUITABLE FOR A PARTICULAR PURPOSE; THE LICENSOR DOES NOT WARRANT THAT USE OF THE PRODUCT WILL NOT INFRINGE UPON THIRD-PARTY RIGHTS; THE LICENSOR SHALL NOT BE LIABLE TO THE LICENSEE OR ANY THIRD PARTY FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, OR PUNITIVE DAMAGES ARISING FROM THE USE OF THE PRODUCT.

5. Termination

Static analysis

No suspicious patterns detected.