Back to skill

Security audit

Ppt Ocr

Security checks for vulnerabilities and agentic risk

Overview

The skill is a straightforward PowerPoint OCR helper, with the main caution that it uses a third-party MinerU CLI and service for document processing.

Before installing, confirm you trust MinerU/OpenDataLab and the mineru-open-api package source. Do not process confidential decks unless third-party OCR processing is acceptable, prefer a pinned or isolated install, and avoid running the global install with elevated privileges.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Third-Party CLI Installation Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15–18
Vulnerability Type: Unpinned third-party dependencies
Risk Level: Medium

bash
npm install -g mineru-open-api
# or via Go (macOS/Linux):
go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@latest

Technical Analysis

The installation instructions retrieve and execute third-party software without pinning it to a reviewed, immutable version. The npm command resolves the package version available under the package registry's current default tag, while the Go command explicitly requests @latest.

Consequently, the installed code can change without any corresponding modification to this skill. If the package publisher account, source repository, package registry, or release pipeline is compromised, a malicious release could be delivered to users following these instructions. npm lifecycle scripts or Go build-time behavior may execute during installation, and the resulting CLI executes with the privileges of the invoking user.

The npm command also requests a global installation. Depending on the host's npm configuration, users may run it with elevated privileges, which would increase the potential impact. The documentation does not explicitly instruct users to use elevated privileges, so privilege escalation is not treated as a confirmed behavior.

Attack Path

  1. An attacker compromises the upstream package publisher, repository, registry account, or release pipeline.
  2. The attacker publishes a malicious version of mineru-open-api or modifies the release resolved by @latest.
  3. A user follows the documented installation command.
  4. The package manager retrieves the malicious release because no reviewed version or integrity value is pinned.
  5. Malicious code executes during installation or when the installed CLI is invoked.
  6. The code gains access to resources available to the invoking user, potentially including submitted presentation files, generate ...[truncated 809 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin both installation methods to specific versions that have been reviewed:
    bash
    npm install -g mineru-open-api@<reviewed-version>
    go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@<reviewed-version>
    
  2. Prefer immutable release identifiers, such as a verified semantic version or commit digest, rather than latest or an implicit registry tag.
  3. Publish expected package checksums or signature-verification instructions and require verification before installation.
  4. Use dependency lockfiles and integrity metadata where installation is managed by a project rather than performed globally.
  5. Avoid global npm installation when possible. Use a project-local dependency or an isolated container or virtual environment with minimal filesystem and network permissions.
  6. Do not run installation commands with administrative privileges unless strictly necessary.
  7. Document a controlled upgrade process in which new releases are reviewed, verified, and tested before updating the pinned version.
  8. Run the OCR CLI with only the minimum required access and avoid exposing unrelated credentials in its environment.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs users to run mineru-open-api extract on local files or remote URLs using a required API token, which strongly implies document contents are sent to MinerU's external service for processing. Because the documentation does not clearly disclose that potentially sensitive slide contents may leave the local environment, users could unknowingly transmit confidential presentations to a third party.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. The line states a default language of ch and only mentions en as an alternative, which can impose a specific locale preference without explicit user choice or documented regional justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.