Back to skill

Security audit

Ntriq X402 Document Intel

Security checks for vulnerabilities and agentic risk

Overview

This skill provides a paid document-analysis API, but it misleadingly says there is no cloud upload while instructing users to send document images to a remote service.

Review before installing or using. Treat this as an external paid document-processing service, not local-only processing. Do not submit confidential or regulated documents unless you are comfortable with x402.ntriq.co.kr receiving them, and confirm each wallet payment before use.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill markets the service as using 'local AI vision' and 'no cloud upload,' but the documented invocation sends the document image or base64 content to a remote HTTPS endpoint for processing. This can mislead users into transmitting sensitive documents such as invoices, contracts, or forms without clear disclosure that data leaves the local environment and is handled by a third-party service.

Static analysis

No suspicious patterns detected.