Back to skill

Security audit

Doc OCR

Security checks for vulnerabilities and agentic risk

Overview

This OCR skill is coherent, but users should review it because it sends or enables processing of potentially sensitive documents through a third-party MinerU tool and recommends mutable global installs.

Install only if you are comfortable with MinerU handling the documents you process. Avoid sending confidential legal, business, medical, or personal files unless you have reviewed MinerU's data handling terms. Prefer a pinned, reviewed mineru-open-api version in an isolated environment, and set the language flag explicitly.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Third-Party Executable Dependencies

Content
View full analysis
Remediation
View remediation
``` 3. Update the Skill metadata so its installation declarations use the same reviewed versions rather than mutable package references. 4. Publish expected cryptographic checksums or signature-verification instructions and require users to verify downloaded artifacts before execution. 5. Document the reviewed package provenance, release date, source repository, and integrity information. 6. Avoid global installation where practical. Prefer an isolated environment, container, or dedicated low-privilege account with access only to the documents and output directories required for OCR. 7. Review npm lifecycle scripts, Go build dependencies, and transitive dependencies before approving each upgrade. Perform upgrades deliberately rather than automatically tracking the latest release. 8. Ensure that the OCR executable receives only the minimum required credentials and file access. Do not run installation or document processing as an administrator unless strictly necessary. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly states that supported input includes local files or URLs and requires a MinerU API token, but it does not warn users that document contents may be transmitted to an external OCR service. This creates a real confidentiality and privacy risk because users may submit sensitive Word documents without realizing they are leaving the local environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill states that the language hint default is ch and only mentions using en for English, which imposes a specific locale behavior by default. This can violate language/locale policy expectations when users are not given a neutral default or explicit opt-in choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.