Back to skill

Security audit

Pptx Ocr

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward PowerPoint OCR helper for MinerU, with no hidden code or persistence, but users should understand that OCR may involve sending presentations to an external service.

Install and run this only if you are comfortable using MinerU for OCR. Avoid processing confidential presentations unless your policy allows third-party OCR, prefer pinned or reviewed CLI versions when possible, and keep the MINERU_TOKEN scoped and protected.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Third-Party CLI Installation Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 14-17
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: Medium

bash
npm install -g mineru-open-api
# or via Go (macOS/Linux):
go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@latest

Technical Analysis

The installation instructions retrieve mutable dependency versions without pinning them to a previously audited release or commit. The npm command implicitly installs the package version currently associated with the registry's default distribution tag, while the Go command explicitly selects @latest.

Consequently, the code installed by these commands can change after the Skill has been reviewed. If the npm package, upstream repository, maintainer account, release pipeline, or package distribution channel is compromised, a malicious release could be delivered to users following these instructions. The global npm installation increases exposure because installation and package lifecycle code executes with the invoking user's permissions and places executables in a shared command path.

Attack Path

  1. An attacker compromises the upstream npm package, source repository, maintainer credentials, or release pipeline.
  2. The attacker publishes a malicious version and makes it the version resolved by the npm default tag or Go's @latest selector.
  3. A user follows the installation commands in SKILL.md.
  4. The package manager retrieves and installs the attacker-controlled release without validating a documented version, commit, checksum, or signature.
  5. Malicious installation hooks or CLI code executes with the user's privileges.
  6. The payload may access files available to that user, steal the configured MINERU_TOKEN, inspect submitted presentations, alter generated OCR output, or execute additional local commands.

Impact Assessment

Successful exploitation could provide arbitrary co ...[truncated 544 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace mutable dependency references with an exact, reviewed version:
    bash
    npm install mineru-open-api@EXACT_REVIEWED_VERSION
    go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@EXACT_REVIEWED_VERSION
    
  2. Pin the Go installation to an immutable audited commit when reproducibility is required.
  3. Document expected artifact checksums or signature-verification procedures and verify downloaded releases before execution.
  4. Prefer a project-local npm installation with a lockfile over global installation, reducing shared command-path exposure and improving reproducibility.
  5. Review the package's lifecycle scripts, transitive dependencies, release provenance, and publisher identity before approving a version.
  6. Use a restricted, non-administrative account or isolated environment to install and run the CLI.
  7. Avoid exposing unrelated secrets to the process, scope the MinerU token to the minimum required permissions, and rotate it if dependency compromise is suspected.
  8. Establish a controlled update process in which newer releases are security-reviewed before the pinned version is changed.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs users to authenticate with a third-party service and submit either local PPTX files or remote URLs for OCR, but it never clearly discloses that slide contents may be transmitted off-host to MinerU. Because presentations often contain sensitive business, legal, or personal information, this omission can lead users to unknowingly exfiltrate confidential data to an external processor.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation states --language has default ch, which imposes a language/locale choice by default. The policy allows language constraints when users are given a clear choice or the constraint is justified; here, the default is presented without justification or opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.