Back to skill

Security audit

文档识别-表格识别(invoice-ocr-xy)翔云平台

Security checks for vulnerabilities and agentic risk

Overview

This OCR skill appears to do what it says, but it stores OCR credentials in a local plaintext config file and uploads selected documents to a third-party service without a clear privacy warning.

Review this skill before installing if you will process sensitive documents. Only point it at files you are allowed to upload to NetOCR, understand that OCR use may incur provider charges, and avoid entering production credentials unless you are comfortable with them being stored in the skill directory as plaintext config.json.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/recognize_doc.py:66
Finding

OCR Credentials Stored in Plaintext with Insufficient Access Controls

Content
View full analysis

Vulnerability Details

File Location: scripts/recognize_doc.py, lines 66–73; related credential handling at lines 371–376 and 383–386
Vulnerability Type: Plaintext sensitive-data storage and credential disclosure
Risk Level: Medium

Vulnerable Code

python
def save_config(config: dict):
    """保存配置文件"""
    config_path = Path(__file__).parent.parent / "config.json"
    with open(config_path, 'w', encoding='utf-8') as f:
        json.dump(config, f, indent=2, ensure_ascii=False)

Related credential collection and display logic:

python
netocr_key = input("netocr_key: ").strip()
netocr_secret = input("netocr_secret: ").strip()
config = {
    "netocr_key": netocr_key,
    "netocr_secret": netocr_secret
}
save_config(config)
python
print(f"  OCR Key: {config.get('netocr_key', '(未设置)')}")
print(f"  OCR Secret: {'*' * 8 if config.get('netocr_secret') else '(未设置)'}")

Technical Analysis

The configuration routine stores both netocr_key and netocr_secret as unencrypted JSON in the predictable project-root file config.json. The file is opened using the process's default permission behavior, subject to the current umask, rather than being explicitly created with owner-only permissions.

The secret is also collected through input(), which echoes entered characters to the terminal. This can expose it through shoulder surfing, terminal recording, remote-session logging, or screen capture. Although --list-config masks the secret, it prints the complete OCR key.

The bundled config.json contained empty values during the audit, so no active credential was present in the reviewed artifact. The vulnerability arises after a user runs the documented configuration workflow.

The separately flagged Base64 and network behavior is consistent with the declared cloud OCR functionality: complete document bytes are Base64-encoded and sent with the credentials over HTTPS t ...[truncated 1442 chars]

Remediation
View remediation

Remediation Suggestions

  1. Store credentials in an operating-system credential manager or secret-management service rather than in the Skill directory.
  2. If file-based storage is unavoidable, create the file with owner-only permissions such as mode 0600, verify its ownership and permissions before reading it, and reject insecure configurations.
  3. Collect netocr_secret using getpass.getpass() so that it is not echoed to the terminal.
  4. Mask both the OCR key and secret in --list-config; reveal only a minimal suffix if identification is required.
  5. Exclude config.json from source control, backups intended for sharing, Skill packaging, logs, and diagnostic bundles. Provide a separate placeholder such as config.example.json.
  6. Support environment variables or injected runtime secrets for automated deployments.
  7. Document that complete source documents and credentials are transmitted to the third-party NetOCR service, including the destination, billing implications, retention considerations, and required user consent.
  8. Rotate any credentials if a populated configuration file has previously been published, shared, backed up insecurely, or exposed to unauthorized users.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill declares operational behavior that implies file reads, file writes, and outbound network access, but it does not define any explicit tool scope or permission boundaries. That increases the risk of over-broad execution in an agent environment because the agent may be allowed to access more files or network destinations than users expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill says document files will be processed via the Xiangyun OCR API, which implies transmitting document contents to a third-party service, but it does not clearly warn users that potentially sensitive files leave the local system. In the context of OCR on business or personal documents, this omission is particularly risky because uploaded files may contain PII, financial data, contracts, or IDs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill says document files will be processed via the Xiangyun OCR API, which implies transmitting document contents to a third-party service, but it does not clearly warn users that potentially sensitive files leave the local system. In the context of OCR on business or personal documents, this omission is particularly risky because uploaded files may contain PII, financial data, contracts, or IDs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script saves netocr_key and netocr_secret in plaintext to a local config.json file under the project directory, with no warning to the user and no filesystem permission hardening. Any local user, backup process, or accidental repository inclusion could expose the credentials, enabling unauthorized use of the OCR account or associated billing abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script base64-encodes full document contents and sends them, along with the user's OCR credentials, to a third-party service over the network without any explicit consent prompt or warning about external transmission. In a skill context that scans arbitrary local files and folders, this can cause users to unknowingly upload sensitive documents such as contracts, IDs, or financial records to an external provider.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

All natural-language strings in the module docstring and CLI prompts are Chinese, with no alternative language option or opt-in mechanism. That can violate language/locale policy when a skill imposes a single language without user choice or explicit justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.