Back to skill

Security audit

smart ocr

Security checks for vulnerabilities and agentic risk

Overview

This OCR skill has a coherent purpose, but it needs Review because it can read OpenClaw session history and upload selected images to a configurable OCR endpoint without strong scoping or confirmation.

Review before installing. Use this only for documents you are comfortable sending to the configured SmartOCR service, prefer the default HTTPS endpoint or a trusted HTTPS host, avoid the session helper unless you can verify the exact session and image being processed, and use a limited API key. The skill should add stronger session scoping, endpoint validation, and explicit data-transfer confirmation before it is treated as low-risk.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/smartocr_from_session.py:40
Finding

Automatic Session Selection Can Upload Images from an Unrelated Conversation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/smartocr.py:39
Finding

Configurable Plaintext Endpoint Can Expose API Credentials and Sensitive Documents

Content
View full analysis
dict: resp = requests.post( f"{api_url.rstrip('/')}/api/ocr", headers={"X-API-Key": api_key}, json={"image": image}, timeout=timeout, ) resp.raise_for_status() return resp.json() ``` ```python api_key = os.environ.get("SMARTOCR_API_KEY", "") api_url = os.environ.get("SMARTOCR_API_URL", DEFAULT_API_URL) ``` The session helper has the same behavior: ```python def ocr(image_data, api_url, api_key, timeout=60): resp = requests.post( f"{api_url.rstrip('/')}/api/ocr", headers={"X-API-Key": api_key}, json={"image": image_data}, timeout=timeout, ) resp.raise_for_status() return resp.json() ``` ### Technical Analysis Both scripts trust `SMARTOCR_API_URL` without validating its scheme, hostname, port, or final destination. The API key is placed in the `X-API-Key` header, while the complete image is included in the request body. Although the default endpoint uses HTTPS, the configuration accepts plaintext HTTP and the documentation provides an HTTP example for local development. The implementation does not restrict plaintext HTTP to loopback addresses. Consequently, a remote HTTP endpoint can receive both the credential and document without transport encryption. A manipulated environment can also redirect requests to an attacker-controlled HTTPS endpoint. HTTPS protects transport confidentiality but does not establish that an arbitrary configured host is an authorized OCR provider. There is no destination allowlist or explicit confirmation before sending c ...[truncated 1551 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/smartocr.py:2
Finding

Unpinned Runtime Dependency Creates a Supply-Chain Exposure

Content
View full analysis
=3.8" # dependencies = [ # "requests", # ] # /// ``` The same dependency declaration appears in both scripts. The documented invocation uses `uv run`, which can resolve and install the declared dependency at execution time. ### Technical Analysis The dependency is specified only by package name, without an exact version, lockfile, or integrity hash. As a result, future executions may install a version of `requests` or its transitive dependencies that was not reviewed during this audit. This is not evidence that the current `requests` package is malicious. The risk arises because runtime dependency resolution permits the effective code executed by the Skill to change independently of the reviewed project files. Package-registry compromise, a malicious future release, dependency-resolution manipulation, or an incompatible update could affect execution. Imported Python packages execute initialization code within the caller's process. Such code inherits the script's access to environment variables, local files, network connectivity, and session data. ### Attack Path 1. The Skill is invoked using `uv run` in an environment where the dependency is not already locked and cached. 2. The package resolver queries its configured package source and selects the then-current compatible releases. 3. A compromised registry, malicious package release, altered package source, or compromised transitive dependency supplies unsafe code. 4. The dependency is installed and imported by the OCR script. 5. Initialization or runtime code executes with the user's permissions. 6. Malicious dependency code can read `SMARTOCR_API_KEY`, inspect files accessible to the process, access session data, or ...[truncated 562 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tainted flow: 'api_key' from os.environ.get (line 65, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/smartocr.py (reported line 41)May include surrounding context.

python
Returns:
        包含 ocr_type 和 content 的字典
    """
    resp = requests.post(
        f"{api_url.rstrip('/')}/api/ocr",
        headers={"X-API-Key": api_key},
        json={"image": image},

Tainted flow: 'api_key' from os.environ.get (line 134, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/smartocr_from_session.py (reported line 98)May include surrounding context.

python
def ocr(image_data, api_url, api_key, timeout=60):
    """调用 SmartOCR API。"""
    resp = requests.post(
        f"{api_url.rstrip('/')}/api/ocr",
        headers={"X-API-Key": api_key},
        json={"image": image_data},

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented purpose says the skill processes image URLs and local files, but the skill also states it can scan ~/.openclaw/agents/{agent}/sessions/ and extract recent uploaded images from session JSONL files. This is dangerous because it expands behavior into undeclared access of historical conversation data, potentially collecting sensitive user images and transmitting them to a third-party OCR service without sufficiently explicit disclosure or per-use authorization.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents and enables access to environment variables, local files, and remote network endpoints, but it does not declare any explicit tool scope or permissions boundary. This is dangerous because the agent can read local image files, access session-related paths, and send data to an external OCR API without a clearly declared least-privilege contract, making review, containment, and user consent weaker.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This CLI uploads either a user-supplied image URL or the full contents of a local image file to a remote OCR service, and those images may contain sensitive PII such as vehicle registration documents, receipts, or invoices. The script description and runtime behavior do not present a clear, explicit privacy/data-transfer warning before transmission, which increases the risk of users unknowingly exfiltrating sensitive documents to a third party.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script behavior materially differs from the skill description: instead of only handling explicit user-provided image URLs or local files, it searches OpenClaw session history and extracts recent images automatically. That can cause unintended access to prior conversation attachments and send sensitive documents to a third-party OCR service without clear user intent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Reading OpenClaw session files from disk gives the skill access to historical user content beyond the minimum needed for OCR. In this context, session data may include highly sensitive vehicle documents, invoices, or other attachments, so broad disk access increases privacy and data-exfiltration risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code sends extracted session images to an external OCR API, but there is no explicit user-facing warning or consent flow explaining that conversation attachments will leave the local environment. Because the skill targets vehicle licenses and receipts/invoices, the transmitted images are likely to contain personal, financial, or regulated data, making this especially sensitive.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language description, help text, and runtime messages are all fixed in Chinese, with no indication that users can select another language. Under the stated policy, forcing a specific language without user opt-in is a locale/language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language descriptions, usage text, and error/help strings in this script are presented in Chinese only. There is no indication that the tool is region-specific or that users can opt into another language, which may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.