Back to skill

Security audit

组织机构代码证识别与抽取(ADP)

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate ADP cloud document-extraction skill, but it exposes and documents broader account-level CLI capabilities than the narrow certificate-recognition purpose needs.

Install only if you intend to use Laiye ADP as a cloud service for sensitive business documents and are comfortable giving the CLI broader ADP account capabilities. Prefer npm or verified release artifacts over pipe-to-shell installers, protect the API key, avoid submitting confidential certificates unless your policy allows it, and do not let an agent use custom-app management commands unless you explicitly need that administrative control.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The README advertises a broad, general-purpose document parsing and extraction CLI rather than a narrowly scoped skill for Chinese organization code certificate recognition. This scope mismatch can mislead agents or users into invoking capabilities far beyond the declared purpose, increasing the attack surface and enabling unintended data access or processing paths.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
Including custom application creation, editing, and lifecycle management introduces administrative capabilities unrelated to simple certificate extraction. In an agent context, this broadens authority from document processing to persistent configuration changes, which could be abused to create unsafe extractors, alter workflows, or exfiltrate additional data.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
Application discovery and management features allow enumeration of available apps and access to broader platform capabilities than certificate extraction alone. In a skill intended for a narrow document type, this can facilitate lateral capability discovery and misuse by an agent, especially when combined with remote parsing and custom-app operations.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The README describes a broad, general-purpose ADP CLI with parsing, extraction, task querying, application management, and custom app capabilities, which materially exceeds the manifest’s narrow claim of a skill for Chinese organization code certificate recognition. This scope mismatch is dangerous because agents or users may grant the skill broader trust and operational latitude than intended, enabling use on arbitrary documents and workflows outside the declared purpose.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
Documenting create, update, and delete operations for custom extraction apps gives this skill administrative and extensibility powers that are not justified by a certificate-recognition use case. In an agent context, unnecessary mutation capabilities increase the attack surface and could be abused to alter extraction logic, create new workflows, or delete configurations.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The README encourages remote document submission, asynchronous task processing, and exporting results to disk without any privacy, retention, or sensitive-data handling warnings. Because the described documents can contain business identifiers and personal information, users may unknowingly send or store sensitive data in insecure or noncompliant ways.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The README recommends installing via piped remote shell and PowerShell commands that execute downloaded content directly, without verification or warning. This is dangerous because any compromise of the source repository, network path, or referenced script can lead to immediate arbitrary code execution on the user’s machine.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill instructs users to send certificate images and extracted identity/business fields to an external ADP cloud service without a prominent upfront disclosure of third-party data transfer, retention, and privacy implications. Because the processed documents contain sensitive organizational and personal data, users may unknowingly transmit regulated information off-platform, creating privacy, compliance, and data-governance risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.