Back to skill

Security audit

pdf-ocr-byzhangchong

Security checks for vulnerabilities and agentic risk

Overview

This OCR skill is local and purpose-aligned, but it can recursively create PDF outputs and depends on unpinned third-party OCR installation steps.

Install only if you are comfortable with a local OCR script processing the PDF paths you provide and creating *_ocr.pdf files plus logs. Test on a small folder first, avoid unattended cron use until outputs are verified, choose the correct OCR language with --lang, and prefer a virtual environment with verified or pinned dependency installation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/install_ocr.md:4
Finding

Unverified and Unpinned Third-Party Software Installation

Content
View full analysis

Vulnerability Details

File Location: references/install_ocr.md, lines 4 and 14–15; also referenced by scripts/ocr_batch.py, line 13
Vulnerability Type: Insecure third-party dependency installation
Risk Level: Medium

Vulnerable Code Snippets

references/install_ocr.md, line 4:

text
1. 前往 https://github.com/UB-Mannheim/tesseract/wiki 下载对应 Windows 的 MSI 安装包(通常是 `tesseract‑5.3.1‑setup‑amd64.exe`)。

references/install_ocr.md, lines 14–15:

powershell
python -m pip install --upgrade pip
pip install ocrmypdf

scripts/ocr_batch.py, line 13:

python
"    pip install ocrmypdf\n"

Technical Analysis

The installation documentation instructs users to download and execute a community-distributed Windows installer without providing an immutable artifact URL, expected cryptographic hash, or digital-signature verification procedure. It also installs the latest available ocrmypdf package and its transitive dependencies from PyPI without pinning or lock-file verification.

The GitHub wiki is relevant to the OCR software and is not inherently malicious. Nevertheless, the installation process trusts mutable external content. If the hosting account, release artifact, package, or a transitive dependency were compromised or substituted, malicious code could execute during installation or later when the OCR command is invoked.

Upgrading pip is not required for the Skill's declared OCR functionality and increases the number of components modified. The runtime script itself does not download software automatically; this risk arises when users follow the documented setup instructions.

Attack Path

  1. An attacker compromises or substitutes the referenced installer, the ocrmypdf package, or one of its transitive dependencies.
  2. A user follows the Skill documentation and downloads the executable or runs the unpinned pip install command.
  3. The unverified installer, package build process, or package initialization code ex ...[truncated 1095 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the supported ocrmypdf version and all transitive Python dependencies in a reviewed lock file with hashes.
  2. Replace mutable download guidance with a specific HTTPS release URL from a trusted project-controlled source.
  3. Publish the expected SHA-256 digest for the Windows installer and instruct users to verify it before execution.
  4. Document how to validate the installer's Authenticode signature and expected publisher identity.
  5. Recommend installation in a dedicated virtual environment rather than modifying a global Python environment.
  6. Remove the unconditional python -m pip install --upgrade pip instruction unless a documented minimum version is required.
  7. Prefer invoking python -m pip consistently so dependencies are installed into the intended interpreter.
  8. Update the runtime error message to refer users to the pinned, integrity-verified installation procedure rather than suggesting an unpinned installation command.
  9. Clarify that normal OCR processing is local, while initial dependency installation requires network access and involves third-party supply-chain trust.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

代码的核心能力与声明的前半部分基本一致:它确实对单个或批量 PDF 调用 ocrmypdf 进行 OCR,生成带文字层的 PDF。但声明中明确包含“可导出为 Markdown/纯文本”,而代码没有文本提取、Markdown 转换、文件导出或相关参数/分支处理。这属于对能力的实质性高报,因此应判定为描述与实际行为不完全一致。其余行为如依赖检查、递归批处理和日志记录属于实现细节,不构成额外未声明风险。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes shell-capable commands (openclaw exec python ...) but does not declare any tool scope or allowed tools. In agent environments, missing explicit permission boundaries can let a workflow invoke shell execution without clear policy constraints, increasing the chance of unintended command execution or unsafe composition with other inputs.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/ocr_batch.py (reported line 10)May include surrounding context.

python
def ensure_ocrmypdf():
    """Check if ocrmypdf is installed, otherwise raise informative error."""
    try:
        subprocess.run(["ocrmypdf", "--version"], check=True, stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
    except Exception as e:
        raise RuntimeError(
            "ocrmypdf 未安装或未在 PATH 中。请先运行: \n"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script contains user-facing error/help text in Chinese and defaults OCR language to simplified Chinese via chi_sim, which imposes a specific language/locale choice. Under the policy, locale constraints should be optional or explicitly justified; here the script does not present language choice as an opt-in despite supporting --lang.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/ocr_batch.py (reported line 20)May include surrounding context.

python
def ocr_file(input_pdf: Path, output_pdf: Path, lang: str = "chi_sim"):
    cmd = ["ocrmypdf", "-l", lang, str(input_pdf), str(output_pdf)]
    subprocess.run(cmd, check=True)

def batch_dir(dir_path: Path, lang: str = "chi_sim"):
    for pdf_path in dir_path.rglob("*.pdf"):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

In batch mode, the script recursively traverses a directory tree and writes new OCR output files for every matching PDF without any dry-run, confirmation, exclusion rules, or guard against reprocessing generated files. In an agent setting handling large document trees, this can cause uncontrolled file creation, repeated processing of generated _ocr.pdf files, storage exhaustion, and unintended modification of user workspaces.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file describes scheduled automatic OCR in a teacher-agent workflow, but it does not explicitly warn users that the process will create output files for each PDF and write to a log file. Because the skill can run unattended on whole directories, a brief disclosure about filesystem changes would improve user awareness and reduce surprise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill documentation is written only in Chinese, which constitutes a language-specific constraint in natural-language instructions without any opt-in or indication that the skill is intentionally region-specific. Under the policy, forcing a specific language without user choice or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code invokes an external tool to create an output PDF file, which is a file-write operation covered by the warning requirement for code files. Although the CLI arguments imply output creation, there is no confirmation prompt or explicit user-facing warning in this execution path about writing the destination file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.